CVE-2025-27938

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Apr 15, 2025
Updated: Apr 16, 2025
CWE ID 639

Summary

CVE-2025-27938 is a newly disclosed vulnerability that allows unauthenticated attackers to gain restricted information about a user's smart device collections, also known as "rooms," on affected devices. This issue does not require any form of authentication, making it particularly dangerous as attackers can easily obtain sensitive information without the user's knowledge or consent. The exact impact of this vulnerability depends on the specific smart device models and configurations involved, but it may include revealing details about a user's home automation setup, device names, and potentially even the physical locations of devices within a user's home. Users are advised to update their devices as soon as patches become available to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share