Impact
OpenRemote, an open‑source IoT platform, contains a flaw in the predicted datapoint write endpoint. Prior to version 1.24.1, users who only possess `read:assets` privileges can send HTTP requests to create or modify predicted datapoints. This improper authorization (CWE‑862) lets a non‑privileged user alter forecast data that should be immutable, undermining the integrity of device telemetry and potentially leading to incorrect device behavior or misleading analytics. Version 1.24.1 fixes the issue.
Affected Systems
The issue affects all OpenRemote installations with versions earlier than 1.24.1. The vulnerable component is the predicted datapoint write API exposed through the OpenRemote web service. Versions 1.24.1 and later incorporate the authorization fix described in the commit on 583dbbfb96… .
Risk and Exploitability
The CVSS base score of 4.3 indicates a low‑to‑moderate severity, reflecting that a successful exploit would mainly affect data integrity rather than confidentiality or availability. The EPSS score is reported as less than 1 %, signaling a very low probability of active exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, and no public exploits have been reported. An attacker would need valid authentication with read‑only asset permissions and would target the exposed HTTP endpoint to write predicted datapoints, effectively bypassing proper authorization controls. Overall, the risk is moderate but constrained by the low exploitation likelihood and absence of known attacks.
OpenCVE Enrichment
Github GHSA