Miele manufactures premium household appliances and connected-home infrastructure, including smart-home gateways and laundry management systems that rely on network connectivity and authentication. Its vulnerability profile centers on authentication and authorization weaknesses—such as user-controlled cryptographic keys, cross-site request forgery, and improper permission assignment—that recur across its gateway firmware and application-facing products, reflecting the challenges of securing embedded networked devices and their management interfaces. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Miele over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-20481CRITICAL In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old password. This can be exploited in conjunction with CVE-2019-20480 | Feb 24, 2020 | 9.8 | 31 | NO | NO |
CVE-2022-3589HIGH An API Endpoint used by Miele's "AppWash" MobileApp in all versions was vulnerable to an authorization bypass. A low privileged, remote attacker would have been able to gain read a | Nov 21, 2022 | 8.1 | 27 | NO | NO |
CVE-2019-20480HIGH In MIELE XGW 3000 ZigBee Gateway before 2.4.0, a malicious website visited by an authenticated admin user or a malicious mail is allowed to make arbitrary changes in the "admin pan | Feb 24, 2020 | 8.8 | 27 | NO | NO |
CVE-2022-22521HIGH In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowingly executed with users privileges. An attacker with low pr | Apr 27, 2022 | 7.3 | 24 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Miele.
Media articles that mention a CVE ID that affects a product developed by Miele — matched by CVE ID, not by vendor name.