# Govee IoT takeover flaw patched server-side

Published: 2025-12-18 · Severity: medium
Canonical: https://vorant.io/reports/8dbdb84b-663b-5e99-a91f-f33936b1e081/govee-iot-takeover-flaw-patched-server-side

> A binding flaw in Govee cloud-connected devices allowed attackers to hijack devices remotely; vendor deployed server-side fixes and firmware updates for H6056 lamps.

CERT Polska coordinated disclosure of CVE-2025-10910, a vulnerability in Govee's cloud platform that allows remote attackers to bind legitimate devices to attacker-controlled accounts. The flaw stems from a weak binding process where device association relies on a set of identifiers (device, SKU, type, and client-computed value) that lack cryptographic binding to device secrets. Successful exploitation grants full device control and removes the device from the legitimate owner's account.

The vulnerability was verified on Govee H6056 smart lamps running firmware 1.08.13, though other cloud-connected Govee models may be affected. Govee has deployed server-side security enhancements and pushed automatic firmware updates to most H6056 devices. Users with upgradeable hardware versions (not 1.00.10 or 1.00.11) must manually update via the Govee Home app if automatic patching failed. Devices with hardware versions 1.00.10 or 1.00.11 cannot receive the firmware update due to hardware limitations and remain vulnerable.

## Mentioned in this report

- Vulnerabilities: CVE-2025-10910

Source reporting: https://cert.pl/en/posts/2025/12/CVE-2025-10910

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/8dbdb84b-663b-5e99-a91f-f33936b1e081/govee-iot-takeover-flaw-patched-server-side.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
