Impact
This vulnerability allows an attacker to retrieve stored pins, including the Master Pin, effectively bypassing standard user permissions. The weakness involves credentials that are insufficiently protected, leaving sensitive authentication information exposed. Because the Master Pin provides complete control over the smart home system, its exposure can lead to full device takeover, enabling the attacker to manipulate devices, disable security features, or create persistent access.
Affected Systems
Rently Smart Home versions 20.1.0 and older are affected. The affected product is Rently Smart Home, as issued by Rently. No further product or version details are available in the CVE data.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score is not available, so no exploitation likelihood data is provided. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthorized request to the device's credential storage interface, enabling credential extraction over a compromised or unsecured connection. This can be performed remotely if an attacker can reach the device from a network connected device or via a compromised local device.
OpenCVE Enrichment