SmartHome application has a broken access control vulnerability in its Web API Server
No sign of exploitation. No public exploitation artifact known so far.
The SmartHome app has a security flaw that allows anyone on the same WiFi network to see user accounts and control IoT devices without needing a password. This means attackers can access and manipulate your smart home devices.
A broken access control vulnerability in SmartHome app (Android ≤3.0.42_190515, iOS ≤2.0.22) permits unauthenticated access to the Web API endpoint /smarthome/devicecontrol over HTTP from the local network, enabling account enumeration and unauthorized device control via the HG100 gateway. Attack vector is network-based with low complexity; no authentication or user interaction required; impact spans confidentiality, integrity, and availability across the system.