CVE-2020-9462: Homey Firmware

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue was discovered in all Athom Homey and Homey Pro devices up to the current version 4.2.0. An attacker within RF range can obtain a cleartext copy of the network configuration of the device, including the Wi-Fi PSK, during device setup. Upon success, the attacker is able to further infiltrate the target's Wi-Fi networks.

Affected products

  • Homey Homey Firmware: before 4.2.0 (fixed in 4.2.0)
  • Homey Homey Pro Firmware: before 4.2.0 (fixed in 4.2.0)

Published 2020-06-04. Last modified 2026-06-17.