PT-2026-82102 · Rently · Rently Smart Home
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Rently Smart Home versions 20.1.0 and earlier
Description
Insufficiently protected credentials in the API allow an attacker to retrieve pins, including the Master Pin. This issue enables the override of standard user permissions, potentially granting access to an entire apartment complex from a single resident login. Real-world incidents have been reported where attackers exploited this to retrieve Master Pins across IoT infrastructure.
Recommendations
Update Rently Smart Home to a version later than 20.1.0.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rently Smart Home