"http://<hub_ip_address>/getstarted" allows anyone to become an admin and take over hub

A pin that is printed on the bottom of the hub would be a better failsafe mechanism in case someone locks themselves out. Or having a reset button that someone could hold in order to reset would be ideal.

I wouldn't categorize this as a home security device, however being able to reset / take over a device simply because you're on the same network is a vulnerability. I don't believe other smart hubs can be taken over this easily.

2 Likes

Thanks for the quick response. I tested it and can verify that the "getstarted" page doesn't allow me to register the hub to a new account

3 Likes