Sonoff manufactures a line of smart home automation devices including WiFi-enabled relays and switches such as the TH10 and TH16 product lines, which bundle firmware that handles web-based configuration and control interfaces. The observed vulnerability pattern centers on cross-site scripting flaws in these web interfaces, a recurrent weakness class in devices that expose configuration portals without robust input sanitization. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sonoff over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7470MEDIUM Sonoff TH 10 and 16 devices with firmware 6.6.0.21 allows XSS via the Friendly Name 1 field (after a successful login with the Web Admin Password). | Jan 21, 2020 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sonoff.
Media articles that mention a CVE ID that affects a product developed by Sonoff — matched by CVE ID, not by vendor name.