← back
CVE-2023-4617

Gaining remote control over Govee devices

CVSS 10 CRITICALEPSS 0.6%CWE-863
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 10EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
19 Dec 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values.  This issue affects Govee Home applications on Android and iOS in versions before 5.9.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
Affected products
Govee · Govee Home

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →