CVE-2025-69822

7.4

Atomberg · Erica Smart Fan

A vulnerability in Atomberg Erica Smart Fan firmware version V1.0.36 allows unauthenticated attackers to trigger a denial of service via crafted deauthentication frames.

Executive summary

A critical security flaw in the Atomberg Erica Smart Fan firmware allows unauthenticated attackers to cause a denial of service through crafted network frames.

Vulnerability

The firmware is susceptible to a denial of service attack where an unauthenticated attacker can send crafted deauthentication frames to the device, resulting in service disruption.

Business impact

The exploitation of this vulnerability results in a denial of service, rendering the smart fan unresponsive to user commands. Given the CVSS score of 7.4, this poses a significant risk to operational availability and device management, potentially causing frustration and loss of functionality for end users.

Remediation

Immediate Action: Contact Atomberg support or monitor the official vendor portal for the release of a firmware update that addresses this vulnerability.

Proactive Monitoring: Monitor network traffic for an unusual volume of deauthentication frames targeting smart devices within the environment.

Compensating Controls: Isolate smart devices on a dedicated, restricted VLAN to limit the exposure of the device management interface to untrusted network segments.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as detailed in the security assessment report provided by the researcher at the referenced GitHub repository.

Analyst recommendation

Due to the availability of a public proof-of-concept, the risk of exploitation is elevated. Administrators should prioritize network segmentation for IoT devices while awaiting an official firmware patch from Atomberg to permanently remediate the issue.

Sources