Lutron develops lighting control and building automation products including the HomeWorks QS and RadioRA 2 system lines, where disclosed vulnerabilities center on hard-coded credentials and exposure of sensitive information in firmware and device configuration. These weaknesses reflect the embedded and networked nature of building automation equipment, where credential management and secure communication boundaries are critical to maintaining isolation between management and user interfaces. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lutron over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-8880HIGH Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) doesn't check for correct user authentication before showing the /deviceIP information, which leads to internal network inf | Apr 23, 2018 | 7.5 | 39 | NO | YES |
CVE-2018-11682CRITICAL Default and unremovable support credentials allow attackers to gain total super user control of an IoT device through a TELNET session to products using the Stanza Lutron integrati | Jun 2, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-11681CRITICAL Default and unremovable support credentials (user:nwk password:nwk2) allow attackers to gain total super user control of an IoT device through a TELNET session to products using th | Jun 2, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-11629CRITICAL Default and unremovable support credentials (user:lutron password:integration) allow attackers to gain total super user control of an IoT device through a TELNET session to product | Jun 2, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-7276HIGH An issue was discovered on Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) devices. Remote attackers can obtain potentially sensitive information via a /DbXmlInfo.xml requ | Feb 21, 2018 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lutron.
Media articles that mention a CVE ID that affects a product developed by Lutron — matched by CVE ID, not by vendor name.