Wizconnected's vulnerability footprint centers on a narrow range of smart lighting and connected color products, including the A60 color bulb line and associated firmware, where the durable signal reflects inadequate protection of sensitive data in storage and transit. The recurring weakness classes—cleartext storage of sensitive information and exposure of sensitive data to unauthorized actors—suggest authentication and encryption gaps typical of consumer IoT devices with minimal security hardening. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wizconnected over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11923MEDIUM An issue was discovered in WiZ Colors A60 1.14.0. API credentials are locally logged. | Apr 2, 2021 | 5.5 | 19 | NO | NO |
CVE-2020-11924MEDIUM An issue was discovered in WiZ Colors A60 1.14.0. Wi-Fi credentials are stored in cleartext in flash memory, which presents an information-disclosure risk for a discarded or resold | Apr 2, 2021 | 5.5 | 16 | NO | NO |
CVE-2020-11922MEDIUM An issue was discovered in WiZ Colors A60 1.14.0. The device sends unnecessary information to the cloud controller server. Although this information is sent encrypted and has low r | Apr 2, 2021 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wizconnected.
Media articles that mention a CVE ID that affects a product developed by Wizconnected — matched by CVE ID, not by vendor name.