Govee cloud-connected devices vulnerable to account takeover via flawed binding process…
Govee cloud-connected devices vulnerable to account takeover via flawed binding process allowing attackers to steal device control from legitimate owners.
CERT Polska coordinated disclosure of CVE-2025-10910, a critical vulnerability in Govee's cloud platform affecting devices with cloud connectivity. The flaw exists in the device binding process, where server-side APIs accept device association using identifiers (device, sku, type) and a client-computed value that lack cryptographic binding to device-originating secrets. This allows remote attackers to bind existing online Govee devices to attacker-controlled accounts, granting full device control and removing the device from the legitimate owner's account.
The vulnerability was verified on the Govee H6056 lamp running firmware 1.08.13, though other cloud-connected Govee models may be affected. The vendor has deployed server-side security enhancements and pushed automatic firmware updates for the H6056 model, successfully patching most devices. Users with upgradeable hardware versions must manually update through the Govee Home app while maintaining WiFi connectivity.
Devices with hardware versions 1.00.10 or 1.00.11 cannot receive firmware updates due to hardware limitations, leaving those units permanently vulnerable. The disclosure was responsibly reported by researchers from NASK-PIB and coordinated through CERT Polska's CVD process.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2025/12/CVE-2025-10910
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free