CVE-2018-9162: Contec-Touch Smart Home Firmware

Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.

Contec Smart Home 4.15 devices do not require authentication for new_user.php, edit_user.php, delete_user.php, and user.php, as demonstrated by changing the admin password and then obtaining control over doors.

Affected products

Published 2018-03-31. Last modified 2026-06-17.