CVE-2025-8393: Dreame Technology Dreamehome Android App

High severity, CVSS 7.3. EPSS: 0.1% chance of exploitation in the next 30 days.

A TLS vulnerability exists in the phone application used to manage a connected device. The phone application accepts self-signed certificates when establishing TLS communication which may result in man-in-the-middle attacks on untrusted networks. Captured communications may include user credentials and sensitive session tokens.

Affected products

Published 2025-08-08. Last modified 2026-06-17.