VYPR
Vendor

Shelly

Products
6
CVEs
6
Across products
9
Status
Private

Products

6

Recent CVEs

6
  • CVE-2025-12056HigNov 19, 2025
    risk 0.54cvss epss 0.00

    Out-of-bounds Read in Shelly Pro 3EM (before v1.4.4) allows Overread Buffers.

  • CVE-2025-11243HigNov 19, 2025
    risk 0.54cvss epss 0.00

    Allocation of Resources Without Limits or Throttling vulnerability in Shelly Pro 4PM (before v1.6) allows Excessive Allocation via network.

  • CVE-2024-48776HigOct 11, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information via the firmware update process

  • CVE-2023-33383MedAug 2, 2023
    risk 0.38cvss 5.3epss 0.05

    Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition that results in a device reload.

  • CVE-2023-42144MedJan 23, 2024
    risk 0.36cvss 5.5epss 0.00

    Cleartext Transmission during initial setup in Shelly TRV 20220811-15234 v.2.1.8 allows a local attacker to obtain the Wi-Fi password.

  • CVE-2023-42143MedJan 23, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Integrity Check in Shelly TRV 20220811-152343/v2.1.8@5afc928c allows malicious users to create a backdoor by redirecting the device to an attacker-controlled machine which serves the manipulated firmware file. The device is updated with the manipulated firmware.