Nightowlsp develops smart doorbell products, notably the WDB-20 series, with a narrow vulnerability footprint concentrated on authentication and credential-handling weaknesses. The recurring exposure centers on authentication bypass via capture-replay attacks and missing authentication controls for critical functions, typical of IoT devices where credential management and session handling present structural risk; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nightowlsp over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-31793HIGH An issue exists on NightOwl WDB-20-V2 WDB-20-V2_20190314 devices that allows an unauthenticated user to gain access to snapshots and video streams from the doorbell. The binary app | May 6, 2021 | 7.5 | 23 | NO | NO |
CVE-2020-28713MEDIUM Incorrect access control in push notification service in Night Owl Smart Doorbell FW version 20190505 allows remote users to send push notification events via an exposed PNS server | Jun 8, 2021 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nightowlsp.
Media articles that mention a CVE ID that affects a product developed by Nightowlsp — matched by CVE ID, not by vendor name.