CVE-2025-53649: Medium severity switchBot SwitchBot App vulnerability
"SwitchBot" App for iOS/Android contains an insertion of sensitive information into log file vulnerability in versions V6.24 through V9.12. If this vulnerability is exploited, sensitive user information may be exposed to an attacker who has access to the application logs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53649?
CVE-2025-53649 is considered a high severity vulnerability due to the potential exposure of sensitive user information.
How do I fix CVE-2025-53649?
To fix CVE-2025-53649, update the SwitchBot App to a version later than V9.12.
What types of sensitive information are affected by CVE-2025-53649?
CVE-2025-53649 affects sensitive user information that can include personal data logged by the SwitchBot App.
Who is affected by CVE-2025-53649?
Users of the SwitchBot App running versions V6.24 through V9.12 are affected by CVE-2025-53649.
Can CVE-2025-53649 be exploited remotely?
CVE-2025-53649 requires an attacker to have access to the application logs to exploit the vulnerability.