CVE-2019-11894: Bosch Smart Home Controller Firmware

Medium severity, CVSS 5.7. EPSS: 0.5% chance of exploitation in the next 30 days.

A potential improper access control vulnerability exists in the backup mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in unauthorized download of a backup. In order to exploit the vulnerability, the adversary needs to download the backup directly after a backup triggered by a legitimate user has been completed.

Affected products

  • Bosch Smart Home Controller Firmware: before 9.8.905 (fixed in 9.8.905)

Published 2019-05-29. Last modified 2026-06-17.