Rently Smart Home leaks Master Pin credentials
A credential-protection flaw in Rently Smart Home devices could let attackers retrieve master PINs and override user access, already patched by the vendor.
CISA disclosed a vulnerability (CVE-2026-75960) affecting Rently Smart Home versions 20.1.0 and prior, classified as Insufficiently Protected Credentials (CWE-522). Successful exploitation could allow an attacker to retrieve sensitive PIN data, including the Master Pin, effectively overriding standard user permission controls on affected smart home/lock systems. This could have significant physical security implications for residential or commercial properties relying on Rently's smart access products.
The vulnerability affects devices deployed primarily in the United States and India, with Rently headquartered in the U.S. The affected sectors per CISA's designation include Commercial Facilities, Communications, and Information Technology. Rently patched the issue in late June, and no user action is required beyond ensuring devices have received the update. CISA states there is no known public exploitation of this vulnerability at this time.
The vulnerability was responsibly reported to CISA by researcher Berk Dusunur. CISA's standard ICS mitigation guidance applies: minimizing network exposure of control system devices, isolating them behind firewalls, and using secure remote access methods such as VPNs where necessary.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-01
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free