Yeelight manufactures smart home devices centered on connected lighting and voice-controlled speakers, where its vulnerability disclosures cluster around permission-assignment and component-exposure issues in firmware and Android implementations. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yeelight over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20007MEDIUM Yeelight Smart AI Speaker 3.3.10_0074 devices have improper access control over the UART interface, allowing physical attackers to obtain a root shell. The attacker can then exfilt | May 16, 2019 | 6.8 | 22 | NO | NO |
CVE-2023-42189HIGH Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0 | Oct 10, 2023 | 7.5 | 21 | NO | NO |
CVE-2025-8210MEDIUM A vulnerability was found in Yeelink Yeelight App up to 3.5.4 on Android. It has been classified as problematic. Affected is an unknown function of the file AndroidManifest.xml of | Jul 26, 2025 | 4.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yeelight.
Media articles that mention a CVE ID that affects a product developed by Yeelight — matched by CVE ID, not by vendor name.