ICSA-25-177-02
·
Published 2025-06-26
·
View on CISA ICS-CERT ↗
TrendMakers Sight Bulb Pro
CVSS 7.6
HIGH
Risk Summary
Successful exploitation of these vulnerabilities could allow an attacker to capture sensitive information and execute arbitrary shell commands on the target device as root if connected to the local network segment.
CVEs (2)
Remediations
- TrendMakers did not respond to CISA's request for coordination. Please contact TrendMakers for more information.
- CISA recommends that device users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:
- The encryption key is sent in the clear only during the initial device setup when the Sight Bulb Pro acts as an access point. Take appropriate physical security measures to minimize the risk of remote network captures or monitoring.
- Utilize network monitoring or signature based detection to monitor for malicious activity.
Affected Vendors
TrendMakers
Affected Products (1)
TrendMakers
·
Sight Bulb Pro Firmware ZJ_CG32-2201
<=8.57.83
Affected Sectors
Commercial Facilities
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more