CVE-2026-8374
Received
Received - Intake
Bluetooth Misuse Bypasses SwitchBot Door Lock
Vulnerability report for CVE-2026-8374, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-09
Last updated on: 2026-10-09
Assigner: cirosec GmbH
Description
Description
Misuse and misconfiguration in Bluetooth communication in SwitchBot Door Lock Series allows an attacker to bypass the electronic lock and access controls via a manipulated communication protocol.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| SwitchBot | Lock | Series Lock 0 |
| SwitchBot | Lock | Series Keypad 0 |
| SwitchBot | Lock | Series App 0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1240 | To fulfill the need for a cryptographic primitive, the product implements a cryptographic algorithm using a non-standard, unproven, or disallowed/non-compliant cryptographic implementation. |
| CWE-1204 | The product uses a cryptographic primitive that uses an Initialization Vector (IV), but the product does not generate IVs that are sufficiently unpredictable or unique according to the expected cryptographic requirements for that primitive. |