CVE-2023-33383: Shelly Pro 4pm Firmware

Medium severity, CVSS 5.3. EPSS: 4.7% chance of exploitation in the next 30 days.

Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition that results in a device reload.

Affected products

  • Shelly Pro 4pm Firmware: version 0.11.0 only

Published 2023-08-02. Last modified 2026-06-17.