CVE-2023-42189: Eve Door And Window Firmware

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a crafted script to the KeySetRemove function.

Affected products

  • Eve Eve Door And Window Firmware: affected versions not specified
  • Govee Led Strip Firmware: version 3.00.42 only
  • Nanoleaf Lightstrip Firmware: version 3.5.10 only
  • Orein Smart Bulb Firmware: affected versions not specified
  • Phillips Hue Bridge Firmware: version 1.59.1959097030 only
  • Switchbot HUB2 Firmware: version 1.0-0.8 only
  • Tapo Mini Smart Wi-Fi Plug Firmware: affected versions not specified
  • TP-Link Smart Plug Firmware: affected versions not specified
  • Yeelight Smart Lamp Firmware: version 1.12.69 only

Published 2023-10-10. Last modified 2026-06-17.