VORANT. Threat Intelligence Sign in Get the full feed

Govee IoT takeover flaw patched server-side

medium vulnerability

A binding flaw in Govee cloud-connected devices allowed attackers to hijack devices remotely; vendor deployed server-side fixes and firmware updates for H6056 lamps.

CERT Polska coordinated disclosure of CVE-2025-10910, a vulnerability in Govee's cloud platform that allows remote attackers to bind legitimate devices to attacker-controlled accounts. The flaw stems from a weak binding process where device association relies on a set of identifiers (device, SKU, type, and client-computed value) that lack cryptographic binding to device secrets. Successful exploitation grants full device control and removes the device from the legitimate owner's account.

The vulnerability was verified on Govee H6056 smart lamps running firmware 1.08.13, though other cloud-connected Govee models may be affected. Govee has deployed server-side security enhancements and pushed automatic firmware updates to most H6056 devices. Users with upgradeable hardware versions (not 1.00.10 or 1.00.11) must manually update via the Govee Home app if automatic patching failed. Devices with hardware versions 1.00.10 or 1.00.11 cannot receive the firmware update due to hardware limitations and remain vulnerable.

Mentioned in this report

Vulnerabilities CVE-2025-10910

Source reporting: https://cert.pl/en/posts/2025/12/CVE-2025-10910

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free