CVE-2025-10910
A flaw in the binding process of Govee’s cloud platform and devices allows a remote attacker to bind an existing, online Govee device to the attacker’s account, resulting in full control of the device and removal of the device from its legitimate owner’s account. The server‑side API allows device association using a set of identifiers: "device", "sku", "type", and a client‑computed "value", that are not cryptographically bound to a secret originating from the device itself.
The vulnerability has been verified for the Govee H6056 - lamp device in firmware version 1.08.13, but may affect also other Govee cloud‑connected devices. The vendor is investigating other potentially affected models.
Leer descripción completaMostrar menos
The vendor has deployed server-side security enhancements and automatic firmware updates for model H6056. Most of H6056 devices have been successfully patched through automatic updates. Remaining H6056 users with upgradeable hardware versions must manually update firmware through the Govee Home app while keeping their device WiFi-connected. Users should open the Govee Home app, tap their H6056 device card to enter the device details page, tap the settings icon in the upper right corner, navigate to Device Information section (Firmware Version), and tap the Update button to install the security patch immediately.
Govee H6056 devices with hardware versions 1.00.10 or 1.00.11 cannot receive firmware update due to hardware limitations.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 9.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.39%
- Percentil entre todas las CVEs puntuadas: 31
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access95 % - Impacto principal
T1098.001Additional Cloud Credentialspersistence · privilege escalation90 % - Impacto secundario
T1531Account Access Removalimpact85 %
Vulnerabilidad en API cloud sin autenticación criptográfica permite a atacante remoto en red sin privilegios asociar dispositivo existente a su cuenta. Impactos: toma de control de cuenta (T1098.001) y compromiso de dispositivo IoT (T1531).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (2)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-639
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-10910",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-10910",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-12-18T14:40:37.275880Z"
}
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "cvd@cert.pl",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 9.3,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "cvd@cert.pl",
"affectedData": [
{
"vendor": "Govee",
"modules": [
"firmware"
],
"product": "H6056",
"versions": [
{
"status": "affected",
"version": "1.08.13",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2025-12-18T12:16:07.963",
"references": [
{
"url": "https://cert.pl/en/posts/2025/12/CVE-2025-10910/",
"source": "cvd@cert.pl"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "cvd@cert.pl",
"description": [
{
"lang": "en",
"value": "CWE-639"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A flaw in the binding process of Govee’s cloud platform and devices allows a remote attacker to bind an existing, online Govee device to the attacker’s account, resulting in full control of the device and removal of the device from its legitimate owner’s account.\nThe server‑side API allows device association using a set of identifiers: \"device\", \"sku\", \"type\", and a client‑computed \"value\", that are not cryptographically bound to a secret originating from the device itself.\n\nThe vulnerability has been verified for the Govee H6056 - lamp device in firmware version 1.08.13, but may affect also other Govee cloud‑connected devices. The vendor is investigating other potentially affected models.\n\nThe vendor has deployed server-side security enhancements and automatic firmware updates for model H6056. Most of H6056 devices have been successfully patched through automatic updates. Remaining H6056 users with upgradeable hardware versions must manually update firmware through the Govee Home app while keeping their device WiFi-connected. Users should open the Govee Home app, tap their H6056 device card to enter the device details page, tap the settings icon in the upper right corner, navigate to Device Information section (Firmware Version), and tap the Update button to install the security patch immediately.\n \nGovee H6056 devices with hardware versions 1.00.10 or 1.00.11 cannot receive firmware update due to hardware limitations."
},
{
"lang": "es",
"value": "Una falla en el proceso de vinculación de la plataforma en la nube y los dispositivos de Govee permite a un atacante remoto vincular un dispositivo Govee existente y en línea a la cuenta del atacante, lo que resulta en el control total del dispositivo y la eliminación del dispositivo de la cuenta de su propietario legítimo.\nLa API del lado del servidor permite la asociación de dispositivos utilizando un conjunto de identificadores: 'device', 'sku', 'type', y un 'value' calculado por el cliente, que no están vinculados criptográficamente a un secreto originado desde el propio dispositivo.\n\nLa vulnerabilidad ha sido verificada para el dispositivo Govee H6056 - lámpara en la versión de firmware 1.08.13, pero también puede afectar a otros dispositivos Govee conectados a la nube. El proveedor está investigando otros modelos potencialmente afectados.\n\nEl proveedor ha implementado mejoras de seguridad del lado del servidor y actualizaciones automáticas de firmware para el modelo H6056. La mayoría de los dispositivos H6056 han sido parcheados exitosamente a través de actualizaciones automáticas. Los usuarios restantes de H6056 con versiones de hardware actualizables deben actualizar manualmente el firmware a través de la aplicación Govee Home mientras mantienen su dispositivo conectado a WiFi. Los usuarios deben abrir la aplicación Govee Home, tocar la tarjeta de su dispositivo H6056 para ingresar a la página de detalles del dispositivo, tocar el icono de configuración en la esquina superior derecha, navegar a la sección Información del Dispositivo (Versión de Firmware), y tocar el botón Actualizar para instalar el parche de seguridad inmediatamente.\n\nLos dispositivos Govee H6056 con versiones de hardware 1.00.10 o 1.00.11 no pueden recibir la actualización de firmware debido a limitaciones de hardware."
}
],
"lastModified": "2026-09-30T23:10:00.237",
"sourceIdentifier": "cvd@cert.pl"
}