AI description
CVE-2026-75960 describes an Insufficiently Protected Credentials vulnerability found in Rently Smart Home versions 20.1.0 and earlier. This flaw could enable an attacker to obtain various access pins, including the Master Pin, thereby allowing them to bypass and override standard user permissions within the system. The vendor, Rently, addressed this vulnerability with a patch released in late June. Users are advised to ensure their Rently Smart Home systems are updated to a patched version, though no specific user action is required beyond this update.
- Description
- Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions.
- Source
- ics-cert@hq.dhs.gov
- NVD status
- Received
CVSS 4.0
- Type
- Secondary
- Base score
- 8.7
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
CVSS 3.1
- Type
- Secondary
- Base score
- 8.1
- Impact score
- 5.2
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Severity
- HIGH
- ics-cert@hq.dhs.gov
- CWE-522
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
9
One resident login, an entire apartment complex: the master PIN in Rently’s API (CVE-2026-75960) https://t.co/NnRDbf0Egn
@Dinosn
29 Aug 2026
5177 Impressions
5 Retweets
41 Likes
33 Bookmarks
0 Replies
1 Quote
🚨 Critical CVE-2026-75960 in Rently Smart Home (≤20.1.0) lets attackers steal Master PIN, bypassing controls. Patch to 20.1.1 now! #Infosec #IoT #CVE #SmartHome #Patch https://t.co/0Dx2L3Cvp9
@Payloadcloud
26 Aug 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes