CVE-2021-26638 is an Improper Authentication vulnerability affecting the S&D smarthome (smartcare) application, allowing for authentication bypass and information exposure. This critical vulnerability, with a CVSS score of 9.8, enables remote attackers to gain full control over the home environment, including indoor controls, without requiring any user interaction or prior authentication. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the potential for complete compromise of smart home systems makes this a significant risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.2.48CPE matchmatch criteria | cpe:2.3:a:xisnd:s\&d_smarthome:*:*:*:*:*:android:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.