CVE-2025-6521 Details
Description
During the initial setup of the device the user connects to an access point broadcast by the Sight Bulb Pro. During the negotiation, AES Encryption keys are passed in cleartext. If captured, an attacker may be able to decrypt communications between the management app and the Sight Bulb Pro which may include sensitive information such as network credentials.
A vulnerability exists in the TrendMakers Sight Bulb Pro during the initial setup phase when the device broadcasts an access point. In this phase, AES encryption keys are transmitted in cleartext. If intercepted, an attacker could decrypt communications between the management application and the Sight Bulb Pro, potentially revealing sensitive information such as network credentials. This issue affects Sight Bulb Pro Firmware ZJ_CG32-2201, version 8.57.83 and prior.
Physical security measures should be implemented to reduce the risk of remote interception during the initial setup when the encryption key is transmitted in cleartext. Additionally, network monitoring or signature-based detection can be used to identify and respond to potential exploitation of this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 27, 2025CISA-ADP
Assessed Jun 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-177-02 | [email protected] | AdvisoryBundleRemedy |
| https://www.trendmakerscares.com/Customer-Service-Hours | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-327 | Use of a Broken or Risky Cryptographic Algorithm | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| TrendMakers Sight Bulb Pro | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 27, 2025 | New CVE Received | [email protected] |
Volerion