CVE-2025-8393: Dreame Technology Dreamehome Android App
High severity, CVSS 7.3. EPSS: 0.1% chance of exploitation in the next 30 days.
A TLS vulnerability exists in the phone application used to manage a connected device. The phone application accepts self-signed certificates when establishing TLS communication which may result in man-in-the-middle attacks on untrusted networks. Captured communications may include user credentials and sensitive session tokens.
Affected products
- Dreame Technology Dreamehome Android App: up to and including 2.1.8.8
- Dreame Technology Dreamehome IOS App: up to and including 2.3.4
- Dreame Technology Movahome IOS App: up to and including 1.2.3
Published 2025-08-08. Last modified 2026-06-17.