Govee manufactures smart lighting and home automation products, particularly LED strips and networked lighting controllers, where its disclosed vulnerabilities cluster around access control, resource management, and exposed internal interfaces. The observed weakness classes—including incorrect permission assignment, uncontrolled resource consumption, and exposed dangerous methods—reflect the embedded firmware and cloud-connectivity attack surface typical of consumer IoT devices. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Govee over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-3612HIGH Govee Home app has unprotected access to WebView component which can be opened by any app on the device. By sending an URL to a specially crafted site, the attacker can execute Jav | Sep 11, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-45956HIGH An issue discovered in Govee LED Strip v3.00.42 allows attackers to cause a denial of service via crafted Move and MoveWithOnoff commands. | Oct 30, 2023 | 7.5 | 21 | NO | NO |
CVE-2023-42189HIGH Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0 | Oct 10, 2023 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Govee.
Media articles that mention a CVE ID that affects a product developed by Govee — matched by CVE ID, not by vendor name.