CVE-2026-75960 PUBLISHED

Insufficiently Protected Credentials in Rently Smart Home

Assigner: icscert
Reserved: 18.08.2026 Published: 26.08.2026 Updated: 26.08.2026

Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Rently
Product Smart Home
Versions Default: unaffected
  • affected from 0 to 20.1.0 (incl.)

Solutions

Rently has patched this vulnerability in late June. No user action is required.

For more information, contact Rently (support@rently.com).

Credits

  • Berk Dusunur reported this vulnerability to CISA. finder

References

Problem Types

  • CWE-522: Insufficiently Protected Credentials CWE