Smartthings
Vendor:
First CVE: Apr 9, 2021 · Active for 5 years
21
Total CVEs
More Total CVEs than 94% of tracked products
4.2
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Smartthings over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 9, 2021
5 years ago
Most Recent CVE
Mar 11, 2025
500 days ago
CVE Severity & Scoring
Smartthings21 CVEs
10%
24%
62%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local6 (28.6%)
Network14 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (4.8%)
Attack Complexity
Low21 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None21 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low6 (28.6%)
High0 (0.0%)
None15 (71.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25508CRITICAL Improper privilege management vulnerability in API Key used in SmartThings prior to 1.7.73.22 allows an attacker to abuse the API key without limitation. | Nov 5, 2021 | 9.8 | 29 | NO | NO |
CVE-2025-2233HIGH Samsung SmartThings Improper Verification of Cryptographic Signature Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authenticat | Mar 11, 2025 | 8.8 | 26 | NO | NO |
CVE-2023-21432HIGH Improper access control vulnerabilities in Smart Things prior to 1.7.93 allows to attacker to invite others without authorization of the owner. | Feb 9, 2023 | 7.8 | 24 | NO | NO |
CVE-2022-39871HIGH Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast | Oct 7, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-39868HIGH Improper access control vulnerability in GedSamsungAccount.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast. | Oct 7, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-39867HIGH Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via SHOW_PERSISTENT_BA | Oct 7, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-39866HIGH Improper access control vulnerability in RegisteredEventMediator.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast. | Oct 7, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-39865HIGH Improper access control vulnerability in ContentsSharingActivity.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast. | Oct 7, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-39864HIGH Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows attackers to access sensitive information via implicit intent. | Oct 7, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-30749HIGH Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart devices by bypassing login activity. | Jun 7, 2022 | 7.8 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (21 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (21 CVEs).
Media Mentions
Signals from CVEs in this product scope (21 CVEs).
Top CNAs Publishing CVEs For Smartthings
Top CWEs
Versions
No cataloged versions.