Bluetooth Misconfiguration in SwitchBot Door Lock Series Exposes Vulnerability
CVE-2026-8374

8.5HIGH

Key Information:

Vendor

Switchbot

Vendor
CVE Published:
9 October 2026

What is CVE-2026-8374?

The SwitchBot Door Lock Series is affected by a significant vulnerability due to a misuse and misconfiguration in its Bluetooth communication. This flaw enables attackers to exploit the misconfigured communication protocol to bypass the electronic lock, gaining unauthorized access to the device's controls. Users of the SwitchBot Door Lock Series are urged to investigate their security configurations and apply any available updates to mitigate potential risks.

Affected Version(s)

Lock Series App Android 0 <= 9.2.6

Lock Series Keypad 0 <= 2.7

Lock Series Lock 0 <= 3.4

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aaron Kaiser (Neodyme AG)
Tobias Madl (Neodyme AG)
Justin Mietzner (Neodyme AG)
.