CVE-2019-11896: Bosch Smart Home Controller Firmware

High severity, CVSS 7.1. EPSS: 0.7% chance of exploitation in the next 30 days.

A potential incorrect privilege assignment vulnerability exists in the 3rd party pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.907 that may result in a restricted app obtaining default app permissions. In order to exploit the vulnerability, the adversary needs to have successfully paired an app, which requires user interaction.

Affected products

  • Bosch Smart Home Controller Firmware: before 9.8.907 (fixed in 9.8.907)

Published 2019-05-29. Last modified 2026-06-17.