IM
IronMonkey Threat Research
‹ Back to ICS Advisories

igloohome Smart Lock Mobile Application

MEDIUM
CVSS 5.3
Date 2026-07-28T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-16581 5.3 medium
In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauthorized actor to access functions or backend services that were not sufficiently protected by authentication controls.

// Remediations (2)

Mitigation: For more information, contact igloohome ([email protected]).
For more information, contact igloohome ([email protected]).
Patch: igloohome have enhanced the access control mechanisms on backend services to ensure that only proper
igloohome have enhanced the access control mechanisms on backend services to ensure that only properly authenticated and authorized requests can interact with sensitive functionality. No user interaction is needed.

// References