Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Homey

First CVE: Jun 4, 2020Active for: 6 yearsTotal CVEs: 2

Homey manufactures home-automation hub devices and firmware that serve as a central controller for smart-home ecosystems, with a vulnerability profile centered on the Homey and Homey Pro product lines and their associated firmware. The durable signal reflects weaknesses endemic to IoT gateway platforms: cleartext storage of sensitive information and use of hard-coded credentials, both of which undermine the security of connected device networks that depend on the hub's integrity. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
2
Total CVEs
More Total CVEs than 56% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
5.9
Avg CVSS Score
Higher Avg CVSS Score than 27% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Homey over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 4, 2020
6 years ago
Most Recent CVE
Mar 9, 2021
1,964 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (2 CVEs).

2 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-28952HIGH
An issue was discovered on Athom Homey and Homey Pro devices before 5.0.0. ZigBee hub devices should generate a unique Standard Network Key that is then exchanged with all enrolled
Mar 9, 20217.524NONO
CVE-2020-9462MEDIUM
An issue was discovered in all Athom Homey and Homey Pro devices up to the current version 4.2.0. An attacker within RF range can obtain a cleartext copy of the network configurati
Jun 4, 20204.317NONO
View all 2 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products2 CVEs
50%
50%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (50.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (50.0%)
Attack Complexity
Low2 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (2 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Homey.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Homey — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Homey's Products

View all 1 CNAs →

Top CWEs