CVE-2017-16867: Amazon Key Firmware

Medium severity, CVSS 6.5. EPSS: 2.2% chance of exploitation in the next 30 days.

Amazon Key through 2017-11-16 mishandles Cloud Cam 802.11 deauthentication frames during the delivery process, which makes it easier for (1) delivery drivers to freeze a camera and re-enter a house for unfilmed activities or (2) attackers to freeze a camera and enter a house if a delivery driver failed to ensure a locked door before leaving.

Affected products

  • Amazon Amazon Key Firmware: up to and including 2017-11-16

Published 2017-11-16. Last modified 2026-06-17.