CVE-2025-56562

7.5

Signify · Wiz Connected

Signify Wiz Connected version 1.9.1 contains an incorrect API implementation that allows unauthenticated remote attackers to trigger a denial of service on affected devices using only a MAC address.

Executive summary

An unauthenticated remote denial of service vulnerability in Signify Wiz Connected 1.9.1 poses a significant risk to device availability.

Vulnerability

The vulnerability exists due to an incorrect API implementation that permits unauthenticated remote attackers to disrupt service, requiring only the target device MAC address to initiate the attack.

Business impact

The ability for an unauthenticated attacker to remotely disable Wiz devices can lead to widespread operational disruption and potential loss of control over smart lighting environments. Given the CVSS score of 7.5, this high severity flaw represents a significant risk to system availability and reliability, necessitating immediate attention to prevent malicious service outages.

Remediation

Immediate Action: Monitor vendor communications for the release of a security update or firmware patch that addresses this API flaw.

Proactive Monitoring: Review network access logs for suspicious traffic directed toward the Wiz API endpoints, specifically looking for anomalous requests containing MAC addresses.

Compensating Controls: Isolate Wiz devices on a restricted VLAN to minimize exposure to the public internet and utilize network firewalls to block unauthorized access to the device management APIs.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing Signify Wiz Connected devices should treat this vulnerability with high urgency due to the ease of exploitation. While a specific patch is not yet confirmed, administrators must implement network-level segmentation to restrict device exposure. Monitor for vendor updates and apply them immediately once available to restore the integrity of the device management interface.

Sources