Skip to main content
  1. Home
  2. Smart Home
  3. Web
  4. News

Installing Osram Lightify smart bulbs could gift wrap your Wi-Fi password to hackers

Add as a preferred source on Google

Like a setting out of a horror movie, a recent discovery of potential security flaws in Osram’s Lightify smart light bulbs may give hackers the ability to remotely operate a user’s lights, and even control their network, without asking for approval. Perhaps even more critical, the vulnerabilities — of which nine were found by a security researcher at Rapid7 — could also give unwanted visitors access to a home’s Wi-Fi network. Deral Heiland, the researcher who happened upon the cracks in Osram’s armor, has reportedly informed the manufacturer of the flaws, and has stated that a simple software update coming out in August should fix the problem.

Of the nine vulnerabilities found by Heiland, the one likely responsible for the bulk of the problem lies with the smart bulb’s companion application, which stores unencrypted copies of an owner’s Wi-Fi password. Because of this, hackers could easily obtain this information via the app, which would grant them access to anything connected to the Wi-Fi network. In other words, this is bad.

Recommended Videos

“This is not just about being able to manipulate the light bulbs,” said University College London cybersecurity expert, Professor Angela Sasse. “The vulnerabilities here could give somebody access to control the network itself and that’s a very serious issue. In this day and age, you would regard that as an unacceptable security flaw. It’s a well known thing that you don’t store passwords like that — it’s really elementary.”

Currently, the company says it continues to analyze potential issues with its products and that most of the flaws will likely be resolved come August. For the remaining risks — which reportedly surround the companion ZigBee Hub — the company says it’s working to find a way to develop yet another patch, though it’s uncertain what the patch would actually target.

As smart home technology continues to grow, one of the most important aspects consumers look for is a device’s built-in security. Unfortunately for Osram, until it fixes its issue of unencrypted Wi-Fi passwords, it’s likely few people will be knocking down its door to install a Lightify system.

Rick Stella
Former Associate Editor, Outdoor
Rick became enamored with technology the moment his parents got him an original NES for Christmas in 1991. And as they say…
Beatbot AquaSense X review: The pool cleaner for those that want to be pampered
It's a nothing short of a self-cleaning nirvana for your pool. But as they say, nothing fine comes without a fittingly handsome fee.
Beatbot Aquasense X robot, AstroRinse station and iSkim

view at amazon

Quick take: 

Read more
An unpatched Shark vacuum flaw could put your smart home at risk
The vulnerability affects SharkNinja robot vacuums and stems from a misconfigured cloud security policy rather than a firmware bug.
Shark RV2320S Matrix Self-Emptying Robot Vacuum Featured

Robot vacuums are supposed to clean the house. Turns out this one was mapping it for strangers. Security researchers have disclosed a critical vulnerability affecting SharkNinja's cloud-connected robot vacuums that could allow attackers to remotely access sensitive information, including live camera feeds, home maps, Wi-Fi passwords, and even execute commands on affected devices. More concerningly, the issue reportedly remains unpatched despite being responsibly disclosed to SharkNinja months ago.

How can a vacuum become a spy?

Read more
Google Home Speaker (2026) review: Smarter and punchier, with a subscription pinch
Google's latest smart speaker pairs Gemini with better sound and deeper smart home integration. What's not to love without spending over a $100?
Sphere, Body Part, Finger

View at Amazon

Quick Recap

Read more