CVE-2025-6521

Severity CVSS v4.0:
MEDIUM
Type:
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
Publication date:
27/06/2025
Last modified:
30/06/2025

Description

During the initial setup of the device the user connects to an access <br /> point broadcast by the Sight Bulb Pro. During the negotiation, AES <br /> Encryption keys are passed in cleartext. If captured, an attacker may be<br /> able to decrypt communications between the management app and the Sight<br /> Bulb Pro which may include sensitive information such as network <br /> credentials.