CVE-2017-18642: Syska Smartlight Rainbow Led Smart Bulb Firmware

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Syska Smart Bulb devices through 2017-08-06 receive RGB parameters over cleartext Bluetooth Low Energy (BLE), leading to sniffing, reverse engineering, and replay attacks.

Affected products

  • Syska Smartlight Rainbow Led Smart Bulb Firmware: up to and including 2017-08-06

Published 2020-02-10. Last modified 2026-06-17.