CVE-2021-27289
CVSS 3.1 Score 9.1 of 10 (high)
Details
Summary
CVE-2021-27289 is a vulnerability affecting Zigbee smart home devices manufactured by Ksix. The issue lies in the improper implementation of the Zigbee anti-replay mechanism in the Gateway Module (v1.0.3), Door Sensor (v1.0.7), and Motion Sensor (v1.0.12). As a result, an attacker within wireless range can exploit this vulnerability by resending captured packets with higher sequence numbers, which are incorrectly accepted as legitimate messages by the devices. This enables the attacker to inject spoofed commands without authentication, leading to false alerts and misleading user notifications through the mobile application.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.