← Terug naar overzicht

CISA published advisory ICSA-26-237-01 regarding a high-severity vulnerability in Rently Smart Home versions 20.1.0 and prior. The flaw, tracked as CVE-2026-75960, involves insufficiently protected credentials (CWE-522), allowing an attacker to retrieve pins including the Master Pin and override standard user permissions. The vulnerability carries a CVSS v3.1 score of 8.1 (HIGH) and a CVSS v4.0 score of 8.7 (HIGH). Affected critical infrastructure sectors include Commercial Facilities, Communications, and Information Technology, with deployment in the United States and India. Rently has patched the vulnerability as of late June 2026 with no user action required. The vulnerability was reported to CISA by Berk Dusunur. No known public exploitation has been reported at this time. Users are advised to minimize network exposure and use VPNs for remote access as additional precautions.

Affected products

  • Rently Smart Home <= 20.1.0

Related CVE's

  • CVE-2026-75960

Categories

  • Critical Infrastructure
  • Identity & Access
  • Mobile & IoT