High severity8.1NVD Advisory· Published Feb 4, 2022· Updated Jun 17, 2026
CVE-2018-25029
CVE-2018-25029
Description
The Z-Wave specification requires that S2 security can be downgraded to S0 or other less secure protocols, allowing an attacker within radio range during pairing to downgrade and then exploit a different vulnerability (CVE-2013-20003) to intercept and spoof traffic.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- cpe:2.3:o:silabs:zgm130s037hgn_firmware:s2:*:*:*:*:*:*:*
- cpe:2.3:o:silabs:zgm2305a27hgn_firmware:s2:*:*:*:*:*:*:*
- cpe:2.3:o:silabs:zgm230sb27hgn_firmware:s2:*:*:*:*:*:*:*
- cpe:2.3:o:silabs:zm5101_firmware:s2:*:*:*:*:*:*:*
- cpe:2.3:o:silabs:zm5202_firmware:s2:*:*:*:*:*:*:*
- Range: S2
Patches
Vulnerability mechanics
References
2- www.pentestpartners.com/security-blog/z-shave-exploiting-z-wave-downgrade-attacks/nvdExploitThird Party Advisory
- community.silabs.com/s/share/a5U1M000000knqNUAQ/updated-your-zwave-smart-locks-are-safe-and-securenvdThird Party Advisory
News mentions
0No linked articles in our index yet.