SwitchBot Smart Video Doorbell Active Debug Code Vulnerability Allowing Unauthorized Telnet Access

Vulnerability

A vulnerability in the SwitchBot Smart Video Doorbell firmware, affecting versions prior to 2.01.078, allows an attacker on an adjacent network to connect to the device via Telnet and gain unauthorized access. This issue arises from an active debug code that was inadvertently left in the firmware.

Impact

Exploitation of this vulnerability allows for unauthorized access to the affected Smart Video Doorbell via Telnet.

Remediation

Users are advised to update the firmware of both the base unit and any extension units to the latest version. The developer provides automatic firmware updates.

Added: Nov 26, 2025, 5:17 AM
Updated: Nov 26, 2025, 5:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.5
remediation
7.7
relevance
1.1
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.