{ "schema_version": "1.4.0", "id": "GHSA-xx3m-cmqv-q6w6", "modified": "2022-05-24T17:43:51Z", "published": "2022-05-24T17:43:51Z", "aliases": [ "CVE-2020-28952" ], "details": "An issue was discovered on Athom Homey and Homey Pro devices before 5.0.0. ZigBee hub devices should generate a unique Standard Network Key that is then exchanged with all enrolled devices so that all inter-device communication is encrypted. However, the cited Athom products use another widely known key that is designed for testing purposes: \"01030507090b0d0f00020406080a0c0d\" (the decimal equivalent of 1 3 5 7 9 11 13 15 0 2 4 6 8 10 12 13), which is human generated and static across all issued devices.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-28952" }, { "type": "WEB", "url": "https://developer.athom.com/firmware" }, { "type": "WEB", "url": "https://homey.app/en-us" }, { "type": "WEB", "url": "https://yougottahackthat.com/blog/1260/athom-homey-security-static-and-well-known-keys-cve-2020-28952" } ], "database_specific": { "cwe_ids": [ "CWE-798" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2021-03-09T20:15:00Z" } }