igloohome Smart Lock Mobile Application
MonitorCVSS 5.3ICS-CERT ICSA-26-209-06Jul 28, 2026
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
A vulnerability in igloohome Smart Lock Mobile Application (Android version 3.2.3) allows unauthorized actors to access backend services and functions. The application failed to properly validate authentication on requests to sensitive functionality, allowing attackers to bypass access controls without user interaction. igloohome has enhanced access control mechanisms on backend services to ensure only properly authenticated and authorized requests can interact with sensitive functionality.
What this means
What could happen
An attacker could access backend services and functions without proper authentication, potentially gaining unauthorized control of smart locks or viewing sensitive access information.
Who's at risk
Facility and building managers using igloohome Smart Lock systems with Android mobile applications. This affects access control for any facility relying on the igloohome app for lock management, including commercial buildings, offices, rental properties, and multi-tenant facilities.
How it could be exploited
An attacker with network access could send requests directly to igloohome backend services, bypassing the mobile application's authentication checks. The attacker could then interact with lock control functions or retrieve sensitive data without valid credentials.
Prerequisites
- Network access to igloohome backend services
- No authentication credentials required
remotely exploitableno authentication requiredlow complexity
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (1)
ProductAffected VersionsFix Status
Smart Lock Mobile Application (Android): 3.2.33.2.3Fix available
Remediation & Mitigation
0/2
Do now
0/1WORKAROUNDRestrict network access to igloohome backend services to authorized mobile applications and known device identifiers
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate Smart Lock Mobile Application (Android) to version 3.2.3 or later
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/db5d7d6a-a541-42f5-b404-9b9bedf0afa7Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.