Rently Smart Home
Rently Smart Home vulnerability affects versions 20.1.0 and prior, allowing attackers to retrieve pins and override user permissions. CISA recommends defensive measures to minimize risk.
Intelligence analysis by Qwen 2.5 (3B)
Rently Smart Home has a vulnerability affecting versions 20.1.0 and prior, which could allow attackers to retrieve pins and override user permissions. CISA recommends defensive measures to minimize risk.
This is a problem with a smart home system that lets bad guys get into your home if they know the right password. The company that makes it has fixed it, but you should still be careful to keep your system safe.
Analysis
{"
Vulnerability Details and CVSS Scores":"The vulnerability is CVE-2026-75960, affecting Rently Smart Home versions 20.1.0 and prior. The CVSS v3 base score is 8.1, and the CVSS v4 base score is 8.7, with a high severity level.","
Impact and Mitigation":"An attacker could retrieve pins, including the Master Pin, which could allow them to override standard user permissions. Rently has patched this vulnerability in late June, and no user action is required. Mitigation includes minimizing network exposure, isolating control system networks, and using more secure remote access methods.","
Related Advisories":"CISA has released several advisories related to industrial control system vulnerabilities, including Siemens SIMATIC IoT2050 Advanced, Bendix EC80 Brake ECU, and PayRange API. These advisories provide additional information and recommendations for mitigating risks."}
Key points
- Rently Smart Home versions 20.1.0 and prior are affected by a vulnerability
- The vulnerability allows attackers to retrieve pins and override user permissions
- Rently has patched the vulnerability and no user action is required
- Users should continue to follow recommended security practices
- Several related advisories have been released by CISA
With the patch in place, the risk of this vulnerability being exploited has been reduced. Users should continue to follow recommended security practices to protect their systems.
If the patch was not applied or if the system was not properly isolated, the vulnerability could still be exploited, leading to unauthorized access to sensitive information.



