CVE-2026-8374 PUBLISHED

Misuse and Misconfiguration of Cryptographic Algorithm in Bluetooth Communication

Assigner: cirosec
Reserved: 12.05.2026 Published: 09.10.2026 Updated: 09.10.2026

Misuse and misconfiguration in Bluetooth communication in SwitchBot Door Lock Series allows an attacker to bypass the electronic lock and access controls via a manipulated communication protocol.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/S:P/AU:N/R:I/V:D/RE:H/U:Red
CVSS Score: 8.5

Product Status

Vendor SwitchBot
Product Lock Series Lock
Versions Default: unaffected
  • affected from 0 to 3.4 (incl.)
Vendor SwitchBot
Product Lock Series Keypad
Versions Default: unaffected
  • affected from 0 to 2.7 (incl.)
Vendor SwitchBot
Product Lock Series App
Versions Default: unaffected
  • affected from 0 to 9.2.6 (incl.)

Credits

  • Aaron Kaiser (Neodyme AG) finder
  • Tobias Madl (Neodyme AG) finder
  • Justin Mietzner (Neodyme AG) finder

References

Problem Types

  • CWE-1204 Generation of weak initialization vector (IV) CWE
  • CWE-1240 Use of a cryptographic primitive with a risky implementation CWE

Impacts

  • CAPEC-395 Bypassing Electronic Locks and Access Controls