


Perceptive Security
SOC/SIEM Consultancy

Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's SaveConfigFile() endpoint writes user-supplied numeric c…
Published:
26 May 2026 at 22:00:00
Alert date:
27 May 2026 at 21:06:41
Source:
nvd.nist.gov
Network Infrastructure, Security Tools
Pi.Alert, a WIFI/LAN intruder detection tool, contains a critical vulnerability in its SaveConfigFile() endpoint that allows unauthenticated remote code execution. The vulnerability occurs when user-supplied numeric configuration values are written directly to pialert.conf without validation. Since this configuration file is executed via Python's exec() function every 3-5 minutes by a background cron process, attackers can inject arbitrary Python code. On default installations with PIALERT_WEB_PROTECTION disabled, no authentication is required to exploit this vulnerability. The issue was fixed in version 2026-05-07.
Technical details
Mitigation steps:
Affected products:
Pi.Alert
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44888
https://github.com/leiweibau/Pi.Alert/security/advisories/GHSA-xg85-f8qw-7c5f
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
