← Back

Ecobee

ecobee

4 CVEs • 4 products

Products (4)

Click to collapse
Toggle

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ecobee
1Ecobee3 Lite Firmware
Jun 17, 2026
Aug 3, 2021
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
A heap-based buffer overflow vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HKProcessConfig function of the HomeKit Wireless Access Control setup process. A threat actor can exploit this vulnerability...Show more
A heap-based buffer overflow vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HKProcessConfig function of the HomeKit Wireless Access Control setup process. A threat actor can exploit this vulnerability to force the device to connect to a SSID or cause a denial of service.Show less
1Ecobee
1Ecobee3 Lite Firmware
Jun 17, 2026
Aug 3, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A NULL pointer dereference vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HomeKit Wireless Access Control setup process. A threat actor can exploit this vulnerability to cause a denial of service, forc...Show more
A NULL pointer dereference vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HomeKit Wireless Access Control setup process. A threat actor can exploit this vulnerability to cause a denial of service, forcing the device to reboot via a crafted HTTP request.Show less
1Ecobee
1Ecobee3 Lite Firmware
Jun 17, 2026
Aug 3, 2021
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Hardcoded default root credentials exist on the ecobee3 lite 4.5.81.200 device. This allows a threat actor to gain access to the password-protected bootloader environment through the serial console.
1Ecobee
1Ecobee4 Firmware
Jun 17, 2026
Apr 14, 2020
N/A· v4
7.5 HIGH· v3
2.9 LOW· v2
Ecobee Ecobee4 4.2.0.171 devices can be forced to deauthenticate and connect to an unencrypted Wi-Fi network with the same SSID, even if the device settings specify use of encryption such as WPA2, as long as the competin...Show more
Ecobee Ecobee4 4.2.0.171 devices can be forced to deauthenticate and connect to an unencrypted Wi-Fi network with the same SSID, even if the device settings specify use of encryption such as WPA2, as long as the competing network has a stronger signal. An attacker must be able to set up a nearby SSID, similar to an "Evil Twin" attack.Show less