Shelly develops a focused line of smart relays and wireless control devices, with its vulnerability footprint centered on firmware in its TRV and Pro series products. The observed weakness classes—cleartext transmission of sensitive information, improper integrity validation, and out-of-bounds reads—reflect the embedded device and network-communication challenges typical of IoT and home-automation hardware. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Shelly over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-33383MEDIUM Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition that results in a device reload. | Aug 2, 2023 | 5.3 | 30 | NO | YES |
CVE-2023-42144MEDIUM Cleartext Transmission during initial setup in Shelly TRV 20220811-15234 v.2.1.8 allows a local attacker to obtain the Wi-Fi password. | Jan 23, 2024 | 5.5 | 18 | NO | NO |
CVE-2023-42143MEDIUM Missing Integrity Check in Shelly TRV 20220811-152343/v2.1.8@5afc928c allows malicious users to create a backdoor by redirecting the device to an attacker-controlled machine which | Jan 23, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shelly.
Media articles that mention a CVE ID that affects a product developed by Shelly — matched by CVE ID, not by vendor name.