Metrics
Affected Vendors & Products
Thu, 08 Jan 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 08 Jan 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue discovered in Dyson App v6.1.23041-23595 allows unauthenticated attackers to control other users' Dyson IoT devices remotely via MQTT. | The Dyson MQTT server (2022 and possibly later) allows publications and subscriptions by a client that has the correct values of AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, and device serial number, even if a device (such as a Pure Hot+Cool device) has been removed and is not visible in the supported MyDyson app. This could allow an unexpected actor to obtain control and set the room temperature (up to 37 Celsius) if ownership of the device is transferred without wiping the device. NOTE: the Supplier's position is that this is "a potential vulnerability that dates back 4 years ago in 2022 and we are unable to replicate that anymore." |
| Weaknesses | CWE-420 | |
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 30 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dyson
Dyson app |
|
| Vendors & Products |
Dyson
Dyson app |
Wed, 29 Oct 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 CWE-287 |
|
| Metrics |
cvssV3_1
|
Wed, 29 Oct 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue discovered in Dyson App v6.1.23041-23595 allows unauthenticated attackers to control other users' Dyson IoT devices remotely via MQTT. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-01-08T18:17:27.310Z
Reserved: 2025-08-17T00:00:00.000Z
Link: CVE-2025-56558
Updated: 2025-10-29T20:37:02.049Z
Status : Awaiting Analysis
Published: 2025-10-29T17:15:35.760
Modified: 2026-01-08T19:15:56.413
Link: CVE-2025-56558
No data.
OpenCVE Enrichment
Updated: 2025-10-30T14:38:37Z