VYPR
Vendor

Govee

Products
6
CVEs
5
Across products
9
Status
Private

Products

6

Recent CVEs

5
  • CVE-2023-4617CriDec 19, 2024
    risk 0.65cvss 10.0epss 0.01

    Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values.  This issue affects Govee Home applications on Android…

  • CVE-2025-10910CriDec 18, 2025
    risk 0.60cvss epss 0.00

    A flaw in the binding process of Govee’s cloud platform and devices allows a remote attacker to bind an existing, online Govee device to the attacker’s account, resulting in full control of the device and removal of the device from its legitimate owner’s account. The…

  • CVE-2023-3612HigSep 11, 2023
    risk 0.53cvss 8.2epss 0.00

    Govee Home app has unprotected access to WebView component which can be opened by any app on the device. By sending an URL to a specially crafted site, the attacker can execute JavaScript in context of WebView or steal sensitive user data by displaying phishing content.

  • CVE-2023-45956HigOct 30, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue discovered in Govee LED Strip v3.00.42 allows attackers to cause a denial of service via crafted Move and MoveWithOnoff commands.

  • CVE-2023-42189HigOct 10, 2023
    risk 0.49cvss 7.5epss 0.01

    Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote…