ZDI-26-557: (Pwn2Own) Amazon Smart Plug Insecure Fallback Information Disclosure Vulnerability
Published Aug 12, 2026
·Updated
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Amazon Smart Plug. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.3.
Affected Software
1 affected component
Amazon Smart plug
Event History
Aug 12, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-26-557?
The severity of ZDI-26-557 is rated at 4.3 on the CVSS scale.
2
What does ZDI-26-557 allow attackers to do?
ZDI-26-557 allows network-adjacent attackers to disclose sensitive information without requiring authentication.
3
Which device is affected by ZDI-26-557?
ZDI-26-557 affects the Amazon Smart Plug.
4
Is authentication required to exploit ZDI-26-557?
No, authentication is not required to exploit the ZDI-26-557 vulnerability.
5
When was ZDI-26-557 published?
ZDI-26-557 was published on August 12, 2026.