This issue affects Govee Home applications on Android and iOS in versions before 5.9.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54470 | Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values. This issue affects Govee Home applications on Android and iOS in versions before 5.9. |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 20 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 19 Dec 2024 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values. This issue affects Govee Home applications on Android and iOS in versions before 5.9. | |
| Title | Gaining remote control over Govee devices | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2024-12-20T17:56:46.028Z
Reserved: 2023-08-30T08:30:57.983Z
Link: CVE-2023-4617
Updated: 2024-12-20T17:56:39.389Z
Status : Deferred
Published: 2024-12-19T10:15:13.147
Modified: 2026-04-15T00:35:42.020
Link: CVE-2023-4617
No data.
OpenCVE Enrichment
No data.
EUVD