PT-2025-16370 · Ksix · Ksix Zigbee Smart Home Kit

Published

2025-04-15

·

Updated

2025-04-15

·

CVE-2021-27289

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ksix Zigbee smart home kit versions v1.0.3 through v1.0.12
Description A replay attack issue was discovered in the Zigbee smart home kit, where the anti-replay mechanism based on the frame counter field is improperly implemented. This allows an attacker within wireless range to resend captured packets with a higher sequence number, which the devices incorrectly accept as legitimate messages, enabling spoofed commands to be injected without authentication and triggering false alerts.
Recommendations For version v1.0.3, update the Zigbee Gateway Module to a version with a properly implemented anti-replay mechanism. For version v1.0.7, update the Door Sensor to a version with a properly implemented anti-replay mechanism. For version v1.0.12, update the Motion Sensor to a version with a properly implemented anti-replay mechanism. As a temporary workaround, consider restricting access to the Zigbee network to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-27289

Affected Products

Ksix Zigbee Smart Home Kit