Executive brief
A vulnerability in Signify Wiz Connected smart lighting devices allows an attacker to remotely disable the device. By knowing only the device's hardware (MAC) address, an unauthorized user can trigger a crash or service failure, rendering the smart light unresponsive. This can disrupt home or business operations and require a manual reset to restore functionality.
Technical details
A vulnerability classified as Missing Authentication for Critical Function (CWE-306) exists in the Signify Wiz Connected 1.9.1 API. The flaw allows a remote, unauthenticated attacker to interact with an incorrect API endpoint. By providing the target device's MAC address, the attacker can trigger a Denial of Service (DoS) condition. The attack is conducted over the network and requires no user interaction. While a proof-of-concept is referenced, specific patch details for version 1.9.1 are not explicitly confirmed in the advisory text.
Affected products
- Signify Wiz Connected 1.9.1
Timeline
- 2025-09-16: disclosed
- 2025-09-16: advisory