CVE-2025-6521

HIGH

Sight Bulb Pro - Info Disclosure

Title source: llm
STIX 2.1

Description

During the initial setup of the device the user connects to an access point broadcast by the Sight Bulb Pro. During the negotiation, AES Encryption keys are passed in cleartext. If captured, an attacker may be able to decrypt communications between the management app and the Sight Bulb Pro which may include sensitive information such as network credentials.

Scores

CVSS v3 7.6
EPSS 0.0003
EPSS Percentile 7.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-327
Status published
Products (1)
TrendMakers/Sight Bulb Pro Firmware ZJ_CG32-2201 < 8.57.83
Published Jun 27, 2025
Tracked Since Feb 18, 2026