CVE-2025-56562
7.5Signify · Wiz Connected
Signify Wiz Connected version 1.9.1 contains an incorrect API implementation that allows unauthenticated remote attackers to trigger a denial of service on affected devices using only a MAC address.
Executive summary
An unauthenticated remote denial of service vulnerability in Signify Wiz Connected 1.9.1 poses a significant risk to device availability.
Vulnerability
The vulnerability exists due to an incorrect API implementation that permits unauthenticated remote attackers to disrupt service, requiring only the target device MAC address to initiate the attack.
Business impact
The ability for an unauthenticated attacker to remotely disable Wiz devices can lead to widespread operational disruption and potential loss of control over smart lighting environments. Given the CVSS score of 7.5, this high severity flaw represents a significant risk to system availability and reliability, necessitating immediate attention to prevent malicious service outages.
Remediation
Immediate Action: Monitor vendor communications for the release of a security update or firmware patch that addresses this API flaw.
Proactive Monitoring: Review network access logs for suspicious traffic directed toward the Wiz API endpoints, specifically looking for anomalous requests containing MAC addresses.
Compensating Controls: Isolate Wiz devices on a restricted VLAN to minimize exposure to the public internet and utilize network firewalls to block unauthorized access to the device management APIs.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations utilizing Signify Wiz Connected devices should treat this vulnerability with high urgency due to the ease of exploitation. While a specific patch is not yet confirmed, administrators must implement network-level segmentation to restrict device exposure. Monitor for vendor updates and apply them immediately once available to restore the integrity of the device management interface.