7.3
/ 10
HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Description
A TLS vulnerability exists in the phone application used to manage a connected device. The phone application accepts self-signed certificates when establishing TLS communication which may result in man-in-the-middle attacks on untrusted networks. Captured communications may include user credentials and sensitive session tokens.
AI Analysis
A vulnerability in Dreame Technology's mobile applications allows the acceptance of self-signed TLS certificates, potentially enabling man-in-the-middle attacks. This could expose user credentials and sensitive session tokens if the communication is intercepted on untrusted networks.
Basic Information
ID
CVE-2025-8393
Source
icscert
Published
Aug 8, 2025 at 16:23
Affected Product
Vendor
Dreame Technology
Product
Dreamehome iOS app
Affected Versions
Dreame Technology Dreamehome iOS app 0
Dreame Technology Dreamehome Android app 0
Dreame Technology MOVAhome iOS app 0
Dreame Technology Dreamehome Android app 0
Dreame Technology MOVAhome iOS app 0
CWE Classification
AI Assessment
AI Severity
High
Vendor
Dreame Technology
Product
Dreamehome iOS app, MOVAhome iOS app