CVE-2021-40825 describes a default key vulnerability in nLight ECLYPSE (nECY) system Controllers running software prior to version 1.17.21245.754. The vulnerability stems from the system not forcing a change to a pre-configured key upon initial setup, which is used for secure communication between nECY devices and SensorView software. This is a high-severity vulnerability (CVSS 8.6) with a low attack complexity, allowing remote attackers with IP access to modify lighting conditions or update software on lighting devices by leveraging the default key. While the attacker cannot authenticate to or modify the nECY system controller's configuration, the potential for disruption is significant. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.17.21245.754CPE matchmatch criteria | cpe:2.3:o:acuitybrands:nlight_eclypse_system_controller_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.