Rently Smart Home

Plan PatchCVSS 8.1ICS-CERT ICSA-26-237-01Aug 25, 2026
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Rently Smart Home versions 20.1.0 and earlier contain a permission validation vulnerability (CWE-522) that allows authenticated attackers to access sensitive information and override user permissions. The vulnerability has a CVSS score of 8.1. Rently released a patch in late June addressing this issue.

What this means
What could happen
An attacker with valid user credentials could access sensitive information stored in the Smart Home system and bypass permission controls, potentially exposing tenant or property data and allowing unauthorized modifications to access rules.
Who's at risk
Property managers and facilities operators using Rently Smart Home systems for access control and tenant management should verify patching status. This affects any organization using Rently's platform for property access and credential management.
How it could be exploited
An attacker must first obtain valid user credentials (through phishing, credential reuse, or social engineering). Once authenticated, the attacker can exploit the permission validation flaw to access data beyond their authorized scope or modify access controls for the property.
Prerequisites
  • Valid user account credentials
  • Network access to Rently Smart Home platform
  • Authenticated session to the application
Remotely exploitableRequires valid credentialsAccess control bypassSensitive data exposure
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (1)
ProductAffected VersionsFix Status
Smart Home≤ 20.1.0No fix yet
Remediation & Mitigation
0/3
Do now
0/2
HARDENINGAudit user access logs to identify any unauthorized permission changes or data access during the vulnerability window
HARDENINGReset credentials for any accounts that may have been compromised or used during the vulnerable period
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXVerify that Rently Smart Home systems have been updated to the patched version released in late June
API: /api/v1/advisories/9d334efb-131b-4947-a271-7291759b9935

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Rently Smart Home | CVSS 8.1 - OTPulse