CVE-2026-75960: Insufficiently Protected Credentials in Rently Smart Home
Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
No user action is required per the advisory; however, ensure Rently Smart Home is updated to a version patched in late June to address the Insufficiently Protected Credentials vulnerability affecting versions 20.1.0 and prior.
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The vulnerability requires low-level privileges and does not require user interaction. It is remotely exploitable over the network.
What could an attacker obtain or do?
An attacker could retrieve PINs, including the Master PIN. Access to the Master PIN can override standard user permissions.
Which versions are affected?
Rently Smart Home version 20.1.0 and earlier are affected.