CVE-2026-8374
Received Received - Intake

Bluetooth Misuse Bypasses SwitchBot Door Lock

Vulnerability report for CVE-2026-8374, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: cirosec GmbH

Description

Misuse and misconfiguration in Bluetooth communication in SwitchBot Door Lock Series allows an attacker to bypass the electronic lock and access controls via a manipulated communication protocol.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
SwitchBot Lock Series Lock 0
SwitchBot Lock Series Keypad 0
SwitchBot Lock Series App 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1240 To fulfill the need for a cryptographic primitive, the product implements a cryptographic algorithm using a non-standard, unproven, or disallowed/non-compliant cryptographic implementation.
CWE-1204 The product uses a cryptographic primitive that uses an Initialization Vector (IV), but the product does not generate IVs that are sufficiently unpredictable or unique according to the expected cryptographic requirements for that primitive.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves misuse and misconfiguration in Bluetooth communication for SwitchBot Door Lock Series. An attacker can bypass the electronic lock and access controls by manipulating the Bluetooth communication protocol.

Impact Analysis

An attacker could bypass the lock, gaining unauthorized access to secured areas. This could lead to theft, property damage, or unauthorized entry into private spaces.

Compliance Impact

This vulnerability may violate compliance requirements for physical security controls in GDPR or HIPAA, as unauthorized access could lead to data breaches or unauthorized handling of sensitive information.

Mitigation Strategies

Disable Bluetooth connectivity on affected SwitchBot Door Lock devices until a firmware update is available. Ensure the device is not exposed to untrusted networks or users. Monitor for unauthorized access attempts or unusual activity logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-8374. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart