CVE detail
CVE-2020-9462 — CVE-2020-9462
Published 2020-06-04 · Modified 2026-06-17 · Vendor homey · Product homey_firmware · Source nvd
MEDIUM
severity
CVSS-derived band
0.0032
EPSS probability
exploitation probability, 30d
24.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
An issue was discovered in all Athom Homey and Homey Pro devices up to the current version 4.2.0. An attacker within RF range can obtain a cleartext copy of the network configuration of the device, including the Wi-Fi PSK, during device setup. Upon success, the attacker is able to further infiltrate the target's Wi-Fi networks.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References