Rently Smart Home
Plan PatchCVSS 8.1ICS-CERT ICSA-26-237-01Aug 25, 2026
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Rently Smart Home versions 20.1.0 and earlier contain a permission validation vulnerability (CWE-522) that allows authenticated attackers to access sensitive information and override user permissions. The vulnerability has a CVSS score of 8.1. Rently released a patch in late June addressing this issue.
What this means
What could happen
An attacker with valid user credentials could access sensitive information stored in the Smart Home system and bypass permission controls, potentially exposing tenant or property data and allowing unauthorized modifications to access rules.
Who's at risk
Property managers and facilities operators using Rently Smart Home systems for access control and tenant management should verify patching status. This affects any organization using Rently's platform for property access and credential management.
How it could be exploited
An attacker must first obtain valid user credentials (through phishing, credential reuse, or social engineering). Once authenticated, the attacker can exploit the permission validation flaw to access data beyond their authorized scope or modify access controls for the property.
Prerequisites
- Valid user account credentials
- Network access to Rently Smart Home platform
- Authenticated session to the application
Remotely exploitableRequires valid credentialsAccess control bypassSensitive data exposure
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (1)
ProductAffected VersionsFix Status
Smart Home≤ 20.1.0No fix yet
Remediation & Mitigation
0/3
Do now
0/2HARDENINGAudit user access logs to identify any unauthorized permission changes or data access during the vulnerability window
HARDENINGReset credentials for any accounts that may have been compromised or used during the vulnerable period
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXVerify that Rently Smart Home systems have been updated to the patched version released in late June
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/9d334efb-131b-4947-a271-7291759b9935Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.