CISA Advises on Rently Smart Home Vulnerability Allowing Master Pin Retrieval
CISA has issued an advisory for Rently Smart Home devices, detailing CVE-2026-75960, a vulnerability that could allow attackers to retrieve sensitive pins, including the Master Pin.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released an advisory detailing a critical vulnerability affecting Rently Smart Home devices. Identified as CVE-2026-75960, the flaw resides in versions 20.1.0 and prior of the Rently Smart Home system.
The vulnerability stems from insufficiently protected credentials within the affected devices. This weakness could be exploited by an attacker to retrieve sensitive information, most notably the Master Pin. Successful exploitation would grant the attacker unauthorized access to the system and the ability to override standard user permissions, potentially compromising the security and functionality of the smart home environment.
The CVSS v3.1 base score for this vulnerability is a high 8.1, with a CVSS v4.0 score of 8.7, both categorized as HIGH severity. The attack vector is network-based, requires low complexity, and can be performed with low privileges, making it accessible to a wide range of threat actors. The potential impact includes significant confidentiality and integrity loss, with a high impact on availability.
Rently, the vendor responsible for the smart home devices, has acknowledged the vulnerability and has already released a patch. According to the advisory, the fix was implemented in late June, and no further user action is required to mitigate the risk, provided the devices have been updated.
This advisory impacts devices deployed in Commercial Facilities and Information Technology critical infrastructure sectors, with known deployments in the United States and India. The vulnerability is categorized under CWE-522, Insufficiently Protected Credentials.
While CISA has not reported any known public exploitation targeting this specific vulnerability at this time, the agency strongly recommends that organizations take defensive measures. These include minimizing network exposure for all control system devices, ensuring they are not accessible from the internet, and locating control system networks behind firewalls and isolating them from business networks.
For remote access, CISA advises using more secure methods such as Virtual Private Networks (VPNs), while also emphasizing the need to keep VPNs updated and recognize their security is only as strong as the connected devices. Organizations are encouraged to perform proper impact analysis and risk assessment before deploying any defensive measures.
CISA also reminds users to be vigilant against social engineering attacks, such as unsolicited email messages with suspicious links or attachments. Further recommended practices for industrial control systems security are available on CISA's ICS webpage, including guidance on defense-in-depth strategies and targeted cyber intrusion detection and mitigation.