CVE-2023-42189: Eve Door And Window Firmware
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a crafted script to the KeySetRemove function.
Affected products
- Eve Eve Door And Window Firmware: affected versions not specified
- Govee Led Strip Firmware: version 3.00.42 only
- Nanoleaf Lightstrip Firmware: version 3.5.10 only
- Orein Smart Bulb Firmware: affected versions not specified
- Phillips Hue Bridge Firmware: version 1.59.1959097030 only
- Switchbot HUB2 Firmware: version 1.0-0.8 only
- Tapo Mini Smart Wi-Fi Plug Firmware: affected versions not specified
- TP-Link Smart Plug Firmware: affected versions not specified
- Yeelight Smart Lamp Firmware: version 1.12.69 only
Published 2023-10-10. Last modified 2026-06-17.