Description
Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions.
Published: 2026-08-26
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Risk of unauthorized access via exposed Master Pin
Action: Update Firmware
AI Analysis

Impact

This vulnerability allows an attacker to retrieve stored pins, including the Master Pin, effectively bypassing standard user permissions. The weakness involves credentials that are insufficiently protected, leaving sensitive authentication information exposed. Because the Master Pin provides complete control over the smart home system, its exposure can lead to full device takeover, enabling the attacker to manipulate devices, disable security features, or create persistent access.

Affected Systems

Rently Smart Home versions 20.1.0 and older are affected. The affected product is Rently Smart Home, as issued by Rently. No further product or version details are available in the CVE data.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. The EPSS score is not available, so no exploitation likelihood data is provided. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthorized request to the device's credential storage interface, enabling credential extraction over a compromised or unsecured connection. This can be performed remotely if an attacker can reach the device from a network connected device or via a compromised local device.

Generated by OpenCVE AI on August 26, 2026 at 14:39 UTC.

Remediation

Vendor Solution

Rently has patched this vulnerability in late June. No user action is required. For more information, contact Rently (support@rently.com).


OpenCVE Recommended Actions

  • Apply the vendor‑released firmware patch issued in late June to fix the credential protection flaw.
  • Ensure all related smart‑home components – bridges, controllers, and supporting appliances – are upgraded to the patched firmware revision or newer.
  • Configure network isolation for the smart‑home system, placing the device on a separate VLAN or subnet to limit exposure to potential attackers.

Generated by OpenCVE AI on August 26, 2026 at 14:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Rently
Rently smart Home
Vendors & Products Rently
Rently smart Home

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Description Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions.
Title Insufficiently Protected Credentials in Rently Smart Home
Weaknesses CWE-522
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Rently Smart Home
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-08-26T17:10:54.255Z

Reserved: 2026-08-18T16:32:03.997Z

Link: CVE-2026-75960

cve-icon Vulnrichment

Updated: 2026-08-26T17:10:51.171Z

cve-icon NVD

Status : Deferred

Published: 2026-08-26T14:17:13.220

Modified: 2026-09-08T19:30:43.093

Link: CVE-2026-75960

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:33:02Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials