ics-otregulatorNewsThe Broadside1 min read

CISA Flags Rently Smart Home Credential Flaw

An authenticated attacker can retrieve master pins and override user permissions; Rently patched the flaw in late June with no user action required.


TL;DR

CISA published an advisory for CVE-2026-75960, an insufficiently protected credentials vulnerability (CWE-522, CVSS 8.1) in Rently Smart Home versions 20.1.0 and prior. An authenticated attacker can retrieve pins including the master pin and override user permissions. The product is deployed in commercial facilities and communications infrastructure in the U.S. and India. Rently says the vulnerability was patched in late June and no user action is required, but hasn't specified a patch version number or whether the update is automatic for deployed instances.

CVE-2026-75960, assigned a CVSS v3.1 base score of 8.1 and a CVSS v4 score of 8.7, affects all Rently Smart Home versions through 20.1.0. An attacker with low-privilege authenticated access can retrieve pins (including the master pin) and override standard user permission controls. The vulnerability, classified as CWE-522 (Insufficiently Protected Credentials), was reported to CISA by researcher Berk Dusunur. Rently Smart Home is deployed in commercial facilities, communications, and information technology environments; CISA lists the United States and India as countries where the product is in use.

The remediation section of the advisory states only that Rently "patched this vulnerability in late June" and that "no user action is required." It doesn't identify a specific patch version or build number, and it's unclear whether deployed instances receive the fix through automatic updates. Organizations that rely on Rently Smart Home for physical access control in contractor-managed or federally adjacent facilities should verify directly with Rently (support@rently.com) that their instances are running the patched version. CISA's standard ICS defensive measures apply: isolate the devices behind firewalls and require VPNs for remote access where necessary.


Published ·Deep Fathom