August develops a focused line of smart-home access and connectivity products, including the August Connect bridge and associated firmware, whose vulnerability profile centers on fundamental credential and encryption handling weaknesses. The recurring exposure involves hard-coded credentials, hard-coded cryptographic keys, and missing encryption of sensitive data—a pattern that reflects gaps in secure secrets management across its connected-device ecosystem. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by August over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20100CRITICAL An issue was discovered on August Connect devices. Insecure data transfer between the August app and August Connect during configuration allows attackers to discover home Wi-Fi cre | Jan 2, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-17098MEDIUM Use of hard-coded cryptographic key vulnerability in August Connect Wi-Fi Bridge App, Connect Firmware allows an attacker to decrypt an intercepted payload containing the Wi-Fi net | Sep 30, 2020 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by August.
Media articles that mention a CVE ID that affects a product developed by August — matched by CVE ID, not by vendor name.