"SwitchBot" App for iOS/Android contains an insertion of sensitive information into log file vulnerability in versions V6.24 through V9.12. If this vulnerability is exploited, sensitive user information may be exposed to an attacker who has access to the application logs.
https://www.switchbot.jp/pages/switchbot-app-vulnerability-fix202507
Published: 2025-07-29
Updated: 2025-07-29
Base Score: 4
Vector: CVSS2#AV:L/AC:H/Au:N/C:C/I:N/A:N
Severity: Medium
Base Score: 5.1
Vector: CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity: Medium
Base Score: 5.9
Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Severity: Medium
EPSS: 0.00014