TLS Vulnerability in Dreametech Phone Application for Connected Device Management
CVE-2025-8393

8.5HIGH

What is CVE-2025-8393?

A vulnerability in Dreametech's phone application allows the acceptance of self-signed certificates during TLS communication. This flaw can expose users to man-in-the-middle attacks on untrusted networks, potentially compromising sensitive communications including user credentials and session tokens. Users are urged to be cautious and monitor for updates from Dreametech addressing this issue.

Affected Version(s)

Dreamehome Android app 0 <= 2.1.8.8

Dreamehome iOS app 0 <= 2.3.4

MOVAhome iOS app 0 <= 1.2.3

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dennis Giese reported this vulnerability to CISA.
.
CVE-2025-8393 : TLS Vulnerability in Dreametech Phone Application for Connected Device Management