Ecobee develops a line of smart thermostats and connected home-comfort devices, with observed vulnerabilities clustering around firmware implementations across its Ecobee3 and Ecobee4 product families. The recurring weakness classes—NULL pointer dereferences, out-of-bounds writes, hard-coded credentials, and use of weak cryptographic algorithms—reflect common patterns in embedded firmware where memory-safety constraints and credential handling are challenging. Current severity, exploitation, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ecobee over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27952CRITICAL Hardcoded default root credentials exist on the ecobee3 lite 4.5.81.200 device. This allows a threat actor to gain access to the password-protected bootloader environment through t | Aug 3, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-27954HIGH A heap-based buffer overflow vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HKProcessConfig function of the HomeKit Wireless Access Control setup process. A thre | Aug 3, 2021 | 8.2 | 25 | NO | NO |
CVE-2021-27953HIGH A NULL pointer dereference vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HomeKit Wireless Access Control setup process. A threat actor can exploit this vulnerab | Aug 3, 2021 | 7.5 | 24 | NO | NO |
CVE-2018-6402HIGH Ecobee Ecobee4 4.2.0.171 devices can be forced to deauthenticate and connect to an unencrypted Wi-Fi network with the same SSID, even if the device settings specify use of encrypti | Apr 14, 2020 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ecobee.
Media articles that mention a CVE ID that affects a product developed by Ecobee — matched by CVE ID, not by vendor name.