Description
A flaw in the binding process of Govee’s cloud platform and devices allows a remote attacker to bind an existing, online Govee device to the attacker’s account, resulting in full control of the device and removal of the device from its legitimate owner’s account. The server‑side API allows device association using a set of identifiers: "device", "sku", "type", and a client‑computed "value", that are not cryptographically bound to a secret originating from the device itself. The vulnerability has been verified for the Govee H6056 - lamp device in firmware version 1.08.13, but may affect also other Govee cloud‑connected devices. The vendor is not able to provide a list of affected products, but rolls out a firmware and server-side fixes. Devices that reached end‑of‑life for security support need replacement with newer models supporting updates.
INFO
Published Date :
2025-12-18T11:21:21.272Z
Last Modified :
2025-12-18T14:42:00.480Z
Source :
CERT-PL
AFFECTED PRODUCTS
The following products are affected by CVE-2025-10910 vulnerability.
No data.
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-10910.
| URL | Resource |
|---|---|
| https://cert.pl/en/posts/2025/12/CVE-2025-10910/ |
|