"http://<hub_ip_address>/getstarted" allows anyone to become an admin and take over hub

Quick update: there has been a change in the get started workflow as mentioned in the release notes for 2.3.1. To better align with this change for new users, the find.hubitat.com now redirects to getstarted.hubitat.com.

This change does not pose any security threats, as if the user is not on the local network, no hubs are discovered on step 4 of the "Getting Started" workflow, after selecting "Find Hubs".

For those who may have bookmarked find.hubitat.com as the easy way to discover hubs on the local network, please visit findmyhub.hubitat.com, instead.

2 Likes