CVE-2018-9162: Contec-Touch Smart Home Firmware
Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.
Contec Smart Home 4.15 devices do not require authentication for new_user.php, edit_user.php, delete_user.php, and user.php, as demonstrated by changing the admin password and then obtaining control over doors.
Affected products
- Contec-Touch Smart Home Firmware: version 4.15 only
Published 2018-03-31. Last modified 2026-06-17.