ZDI-CAN-28460: ZDI-26-558: (Pwn2Own) Amazon Smart Plug OTA Update Process Improper Certificate Validation Vulnerability
Published Aug 12, 2026
·Updated
This vulnerability allows network-adjacent attackers to bypass certificate validation for OTA updates on affected installations of Amazon Smart Plug. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8.
Affected Software
1 affected component
Amazon Smart plug
Event History
Aug 12, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-28460?
The severity of ZDI-CAN-28460 is rated at 6.8 according to the CVSS scoring system.
2
What type of attackers can exploit ZDI-CAN-28460?
Network-adjacent attackers can exploit the ZDI-CAN-28460 vulnerability.
3
How does ZDI-CAN-28460 affect Amazon Smart Plug devices?
ZDI-CAN-28460 allows attackers to bypass certificate validation for OTA updates on affected Amazon Smart Plug installations.
4
Is authentication required to exploit ZDI-CAN-28460?
No, authentication is not required to exploit the ZDI-CAN-28460 vulnerability.
5
What can be done to mitigate ZDI-CAN-28460?
Users should ensure that their Amazon Smart Plug devices are updated with the latest firmware to mitigate ZDI-CAN-28460.