Description
Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, password validation process.
Published: 2026-08-26
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Immediate Patch
AI Analysis

Impact

Based on the CVE description, it is inferred that the Bird Home Automation GmbH D1101V‑F device’s key‑derivation and password validation process may allow an attacker to bypass normal authentication checks. This flaw could let an attacker authenticate without a valid password and gain control over the device’s services, potentially exposing control functions, sensor data, and providing a foothold for further attacks on the device or its network.

Affected Systems

Affected devices are the Bird Home Automation GmbH D1101V‑F, firmware identifier 000140. No additional vendor or product details are available. Users should verify that this firmware version is installed.

Risk and Exploitability

The CVSS score is 9.8, EPSS is < 1%, and the vulnerability is not listed in CISA KEV, so the exact exploitation likelihood is low but the severity remains high. Nevertheless, because the flaw permits unauthorized access, the potential impact is significant. No public exploit is documented, but it is inferred that this weakness may be considered high‑value by attackers seeking to control the device.

Generated by OpenCVE AI on September 2, 2026 at 00:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from Bird Home Automation if it contains a fix for this key‑derivation flaw; the specific update is not confirmed by the CVE data.
  • If a firmware update is not yet available, disable remote access or lock down network access to the device until a fix is released.
  • Revoke or reset all passwords on the device and enforce strong authentication policies, ensuring that passwords are hashed securely and key derivation follows best practices.
  • Monitor device logs for suspicious authentication attempts and alert on failures.

Generated by OpenCVE AI on September 2, 2026 at 00:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title Incorrect Access Control in Key Derivation for Bird Home Automation Device

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 26 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Incorrect Access Control in Key Derivation for Bird Home Automation Device
Weaknesses CWE-284

Wed, 26 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, password validation process.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-01T18:27:12.249Z

Reserved: 2023-09-08T00:00:00.000Z

Link: CVE-2023-42179

cve-icon Vulnrichment

Updated: 2026-09-01T18:27:08.277Z

cve-icon NVD

Status : Deferred

Published: 2026-08-26T18:16:25.377

Modified: 2026-09-08T19:29:09.680

Link: CVE-2023-42179

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T00:30:04Z

Weaknesses