SwitchBot Security Bulletins

To continuously improve the security of our products, we publish and update security notices to keep you informed of newly identified security vulnerabilities, affected versions, and available remediations, helping you stay up to date on the security status of our products.      

Internal IDVulnerability DetailsCVSSSeverityPublication DateAcknowledgementsnotes
ORSA-2026-001Description and Impact:Within Bluetooth range of the device, an unauthenticated user may use specific BLE commands to place the nRF52832 into Nordic Legacy DFU mode. Insufficient firmware verification may allow unintended firmware to be installed, potentially affecting device functionality or preventing the device from operating normally.Affected Product: SwitchBot Hub MiniAffected Version: BLE firmware version 68Remediation: The new firmware closes the BLE command entry point to DFU mode and includes the necessary App-side changes to block this update path.Fixed Version: V69-55Fix Date: August 14, 20268.1High20-Sep-26Sungbin Mo (gl4ss), HEXA LABS by CROCUS