---
id: CVE-2026-8374
title: >-
  Misuse and misconfiguration in Bluetooth communication in SwitchBot Door Lock
  Series allows an attacker to bypass the electronic lock and access controls
  via a manipulated communication protocol.
summary: >-
  Misuse and misconfiguration in Bluetooth communication in SwitchBot Door Lock
  Series allows an attacker to bypass the electronic lock and access controls
  via a manipulated communication protocol.
severity: none
cwe:
  - CWE-1204
  - CWE-1240
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T17:07:31.693'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-8374'
references:
  - url: 'https://neodyme.io/en/advisories/cve-2026-8374/'
    label: a341c0d1-ebf7-493f-a84e-38cf86618674
  - url: 'https://neodyme.io/en/blog/switchbot/'
    label: a341c0d1-ebf7-493f-a84e-38cf86618674
tags:
  - nvd
ingestedAt: '2026-10-09T13:58:52.546Z'
---

## Overview

Misuse and misconfiguration in Bluetooth communication in SwitchBot Door Lock Series allows an attacker to bypass the electronic lock and access controls via a manipulated communication protocol.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
