Fibaro develops home automation and smart-building control systems centered on its Home Center product line and related wireless sensor devices, which serve as centralized management hubs for residential and light-commercial deployments. Vulnerabilities affecting this vendor recur around authentication and command-handling weaknesses—including cleartext credential transmission, certificate validation gaps, and command-injection conditions—that reflect the legacy embedded nature and networked attack surface of these always-on control appliances. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fibaro over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-20991HIGH In Fibaro Home Center 2 and Lite devices with firmware version 4.540 and older an authenticated user can run commands as root user using a command injection vulnerability. | Apr 19, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-20990HIGH In Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older an internal management service is accessible on port 8000 and some API endpoints could be accessed wi | Apr 19, 2021 | 7.5 | 25 | NO | NO |
CVE-2021-20992HIGH In Fibaro Home Center 2 and Lite devices in all versions provide a web based management interface over unencrypted HTTP protocol. Communication between the user and the device can | Apr 19, 2021 | 7.5 | 24 | NO | NO |
CVE-2020-9060MEDIUM Z-Wave devices based on Silicon Labs 500 series chipsets using S2, including but likely not limited to the ZooZ ZST10 version 6.04, ZooZ ZEN20 version 5.03, ZooZ ZEN25 version 5.03 | Jan 10, 2022 | 6.5 | 23 | NO | NO |
CVE-2021-20989MEDIUM Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older initiate SSH connections to the Fibaro cloud to provide remote access and remote support capabilities. T | Apr 19, 2021 | 5.9 | 21 | NO | NO |
CVE-2023-34597MEDIUM A vulnerability in Fibaro Motion Sensor firmware v3.4 allows attackers to cause a Denial of Service (DoS) via a crafted Z-Wave message. | Jun 20, 2023 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fibaro.
Media articles that mention a CVE ID that affects a product developed by Fibaro — matched by CVE ID, not by vendor name.