CVE-2020-7470: Sonoff TH10 Firmware

Medium severity, CVSS 4.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Sonoff TH 10 and 16 devices with firmware 6.6.0.21 allows XSS via the Friendly Name 1 field (after a successful login with the Web Admin Password).

Affected products

  • Sonoff TH10 Firmware: version 6.6.0.21 only
  • Sonoff TH16 Firmware: version 6.6.0.21 only

Published 2020-01-21. Last modified 2026-06-17.