Homey manufactures home-automation hub devices and firmware that serve as a central controller for smart-home ecosystems, with a vulnerability profile centered on the Homey and Homey Pro product lines and their associated firmware. The durable signal reflects weaknesses endemic to IoT gateway platforms: cleartext storage of sensitive information and use of hard-coded credentials, both of which undermine the security of connected device networks that depend on the hub's integrity. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Homey over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-28952HIGH An issue was discovered on Athom Homey and Homey Pro devices before 5.0.0. ZigBee hub devices should generate a unique Standard Network Key that is then exchanged with all enrolled | Mar 9, 2021 | 7.5 | 24 | NO | NO |
CVE-2020-9462MEDIUM An issue was discovered in all Athom Homey and Homey Pro devices up to the current version 4.2.0. An attacker within RF range can obtain a cleartext copy of the network configurati | Jun 4, 2020 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Homey.
Media articles that mention a CVE ID that affects a product developed by Homey — matched by CVE ID, not by vendor name.