connected device. The phone application accepts self-signed certificates
when establishing TLS communication which may result in
man-in-the-middle attacks on untrusted networks. Captured communications
may include user credentials and sensitive session tokens.
No analysis available yet.
Vendor Workaround
Dreame Technology did not respond to CISA's request for coordination. Contact Dreame Technology https://support.dreametech.com/hc/en-us directly for more information. Note that MOVA is a subsidiary of Dreame Technology.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23991 | A TLS vulnerability exists in the phone application used to manage a connected device. The phone application accepts self-signed certificates when establishing TLS communication which may result in man-in-the-middle attacks on untrusted networks. Captured communications may include user credentials and sensitive session tokens. |
Tue, 12 Aug 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dreametech
Dreametech dreamehome Android App Dreametech dreamehome Ios App Dreametech movahome Ios App |
|
| Vendors & Products |
Dreametech
Dreametech dreamehome Android App Dreametech dreamehome Ios App Dreametech movahome Ios App |
Fri, 08 Aug 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 08 Aug 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A TLS vulnerability exists in the phone application used to manage a connected device. The phone application accepts self-signed certificates when establishing TLS communication which may result in man-in-the-middle attacks on untrusted networks. Captured communications may include user credentials and sensitive session tokens. | |
| Title | Dreame Technology iOS and Android Mobile Applications Improper Certificate Validation | |
| Weaknesses | CWE-295 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-08-08T19:14:14.004Z
Reserved: 2025-07-30T20:02:25.275Z
Link: CVE-2025-8393
Updated: 2025-08-08T19:14:09.706Z
Status : Deferred
Published: 2025-08-08T17:15:30.187
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-8393
No data.
OpenCVE Enrichment
Updated: 2025-08-12T11:47:27Z
EUVD