← Back to home
ICSA-25-177-02  ·  Published 2025-06-26  ·  View on CISA ICS-CERT ↗

TrendMakers Sight Bulb Pro

CVSS 7.6 HIGH

Risk Summary

Successful exploitation of these vulnerabilities could allow an attacker to capture sensitive information and execute arbitrary shell commands on the target device as root if connected to the local network segment.

Remediations

  • TrendMakers did not respond to CISA's request for coordination. Please contact TrendMakers for more information.
  • CISA recommends that device users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:
  • The encryption key is sent in the clear only during the initial device setup when the Sight Bulb Pro acts as an access point. Take appropriate physical security measures to minimize the risk of remote network captures or monitoring.
  • Utilize network monitoring or signature based detection to monitor for malicious activity.

Affected Vendors

TrendMakers

Affected Products (1)

TrendMakers · Sight Bulb Pro Firmware ZJ_CG32-2201 <=8.57.83

Affected Sectors

Commercial Facilities

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more