Junglewise Threat Intelligence

CVE-2025-56562: Signify Wiz Connected Missing Authentication DoS via MAC address

CVE-2025-56562 · Severity: high · CVSS 7.5 · Published 2025-09-16

Executive brief

A vulnerability in Signify Wiz Connected smart lighting devices allows an attacker to remotely disable the device. By knowing only the device's hardware (MAC) address, an unauthorized user can trigger a crash or service failure, rendering the smart light unresponsive. This can disrupt home or business operations and require a manual reset to restore functionality.

Technical details

A vulnerability classified as Missing Authentication for Critical Function (CWE-306) exists in the Signify Wiz Connected 1.9.1 API. The flaw allows a remote, unauthenticated attacker to interact with an incorrect API endpoint. By providing the target device's MAC address, the attacker can trigger a Denial of Service (DoS) condition. The attack is conducted over the network and requires no user interaction. While a proof-of-concept is referenced, specific patch details for version 1.9.1 are not explicitly confirmed in the advisory text.

Affected products

  • Signify Wiz Connected 1.9.1

Timeline

  • 2025-09-16: disclosed
  • 2025-09-16: advisory

References