Bluetooth Misconfiguration in SwitchBot Door Lock Series Exposes Vulnerability
CVE-2026-8374
8.5HIGH
What is CVE-2026-8374?
The SwitchBot Door Lock Series is affected by a significant vulnerability due to a misuse and misconfiguration in its Bluetooth communication. This flaw enables attackers to exploit the misconfigured communication protocol to bypass the electronic lock, gaining unauthorized access to the device's controls. Users of the SwitchBot Door Lock Series are urged to investigate their security configurations and apply any available updates to mitigate potential risks.
Affected Version(s)
Lock Series App Android 0 <= 9.2.6
Lock Series Keypad 0 <= 2.7
Lock Series Lock 0 <= 3.4
References
CVSS V4
Score:
8.5
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Aaron Kaiser (Neodyme AG)
Tobias Madl (Neodyme AG)
Justin Mietzner (Neodyme AG)
