CVE-2023-42144: Shelly Trv Firmware

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

Cleartext Transmission during initial setup in Shelly TRV 20220811-15234 v.2.1.8 allows a local attacker to obtain the Wi-Fi password.

Affected products

  • Shelly Trv Firmware: version 2.1.8 only

Published 2024-01-23. Last modified 2026-06-17.