CVE-2025-27927
An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API.
An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API.
MEDIUM · CVSS 5.3
EPSS 0.00761
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
Sigma rules0
YARA rules0