CVE-2025-6521
Severity CVSS v4.0:
MEDIUM
Type:
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
Publication date:
27/06/2025
Last modified:
30/06/2025
Description
During the initial setup of the device the user connects to an access <br />
point broadcast by the Sight Bulb Pro. During the negotiation, AES <br />
Encryption keys are passed in cleartext. If captured, an attacker may be<br />
able to decrypt communications between the management app and the Sight<br />
Bulb Pro which may include sensitive information such as network <br />
credentials.
Impact
Base Score 4.0
6.80
Severity 4.0
MEDIUM
Base Score 3.x
7.60
Severity 3.x
HIGH