The vendor explicitly identifies these products as affected by this CVE.
- Wiser iTRV2 All Versions
- Wiser iTRV3 All Versions
- Wiser RTR2 All Versions
- Wiser UFH All Versions
- Wiser 16A Electrical Heat Switch All Versions
- Wiser Boiler Relay All Versions
- Exxact cFMT 16a All Versions
- Elko cFMT 16a All Versions
- Odace cFMT 2a All Versions
- Merten cFMT 16a All Versions
- Merten cFMT 2a All Versions
- Wiser Power Micromodule All Versions
- Summary
- A CWE-120: A buffer overflow vulnerability exists that could cause a denial of service when a malicious device joins the network.
- Remediation
- Customers should immediately apply the following mitigations to reduce the risk of exploit: To keep your Zigbee network safe and prevent unauthorized access: • Restrict device access: Do not allow unknown devices to join your network. • Review hub settings: Check how your Zigbee hub manages device pairing. • Control network availability: Only open the network when adding new devices and close it immediately after. • Use install codes and avoid the well-known key: Whenever possible, use unique install codes for added security. Replace default keys with secure, unique keys.
