ZDI-26-557: (Pwn2Own) Amazon Smart Plug Insecure Fallback Information Disclosure Vulnerability
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Amazon Smart Plug. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.3.
AI Analysis
Technical Summary
This vulnerability in the Amazon Smart Plug involves an insecure fallback mechanism during the distress beaconing process, which can be exploited by network-adjacent attackers to disclose sensitive information without requiring authentication. The fallback to a less secure state exposes information that could be leveraged alongside other vulnerabilities to execute arbitrary code on the device. The vulnerability was reported to Amazon in November 2025 and publicly disclosed in August 2026. A fix is available in version 3.1.212 of the Amazon Smart Plug.
Potential Impact
An attacker within the same network can disclose sensitive information from the Amazon Smart Plug without authentication. While this vulnerability alone does not allow code execution, it can be combined with other vulnerabilities to execute arbitrary code on the device. The confidentiality impact is limited but notable, with no impact on integrity or availability reported.
Mitigation Recommendations
A fix is available in Amazon Smart Plug version 3.1.212. Users and administrators should update to this version to remediate the vulnerability. No additional vendor advisories indicate further mitigation steps or that no action is required.
ZDI-26-557: (Pwn2Own) Amazon Smart Plug Insecure Fallback Information Disclosure Vulnerability
Description
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Amazon Smart Plug. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.3.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in the Amazon Smart Plug involves an insecure fallback mechanism during the distress beaconing process, which can be exploited by network-adjacent attackers to disclose sensitive information without requiring authentication. The fallback to a less secure state exposes information that could be leveraged alongside other vulnerabilities to execute arbitrary code on the device. The vulnerability was reported to Amazon in November 2025 and publicly disclosed in August 2026. A fix is available in version 3.1.212 of the Amazon Smart Plug.
Potential Impact
An attacker within the same network can disclose sensitive information from the Amazon Smart Plug without authentication. While this vulnerability alone does not allow code execution, it can be combined with other vulnerabilities to execute arbitrary code on the device. The confidentiality impact is limited but notable, with no impact on integrity or availability reported.
Mitigation Recommendations
A fix is available in Amazon Smart Plug version 3.1.212. Users and administrators should update to this version to remediate the vulnerability. No additional vendor advisories indicate further mitigation steps or that no action is required.
Technical Details
- Classification
- {"confidence":0.95,"severitySource":"cvss-text","classifier":"rss-v2"}
- Article Source
- {"url":"http://www.zerodayinitiative.com/advisories/ZDI-26-557/","fetched":true,"fetchedAt":"2026-08-12T20:03:21.278Z","wordCount":180}
Threat ID: 6a7cd317bf8831d5391487c2
Added to database: 08/12/2026, 20:09:59 UTC
Last enriched: 08/12/2026, 20:11:42 UTC
Last updated: 08/12/2026, 22:14:56 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.