CVE-2025-8393 Details
Description
A TLS vulnerability exists in the phone application used to manage a connected device. The phone application accepts self-signed certificates when establishing TLS communication which may result in man-in-the-middle attacks on untrusted networks. Captured communications may include user credentials and sensitive session tokens.
A vulnerability has been identified in the Dreamehome and MOVAhome mobile applications for iOS and Android. This vulnerability arises from improper validation of TLS certificates, as the applications accept self-signed certificates when establishing secure communications. This flaw could allow man-in-the-middle attacks on untrusted networks, potentially intercepting sensitive information such as user credentials and session tokens. The affected versions are Dreamehome iOS through 2.3.4, Dreamehome Android through 2.1.8.8, and MOVAhome iOS through 1.2.3.
Dreame Technology has not responded to CISA's request for coordination. Users are advised to contact Dreame Technology directly for more information. CISA recommends minimizing network exposure for all control system devices and systems, ensuring they are not accessible from the Internet. When remote access is required, use more secure methods such as Virtual Private Networks (VPNs).
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 8, 2025CISA-ADP
Assessed Aug 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.dreametech.com/hc/en-us | [email protected] | Vendor |
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-219-06 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Dreamehome | All versions |
CPE
Remediation
| |
| Dreame MOVAhome | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 8, 2025 | New CVE Received | [email protected] |
Volerion