Is Your Home Security System a Hidden Danger?

Understanding the Vulnerability in Shelly Smart Home Devices
Security researchers at a cybersecurity firm have uncovered a significant vulnerability in Shelly smart home products, a well-known European provider of home security systems. These devices are currently used in over 5.2 million homes across Europe. According to Pen Test Partners, the issue creates an invisible backdoor that allows unauthorized access to private homes, which most users might not even be aware of.
The problem lies with the Gen 4 smart home devices from Shelly. Unlike previous models, these devices keep their open wireless access point active even after being connected to a home Wi-Fi network. This means a hidden network continues to run in the background without the user’s knowledge or consent, long after the initial setup.
The Risks of Leaving Access Points Open
This design flaw poses a serious physical security risk. An individual outside a home could potentially use the resident’s Wi-Fi network to unlock doors, open garage doors, or gain access to gates, increasing the risk of burglary and break-ins. However, the implications go beyond just this specific issue.
Pen Test Partners conducted a broader investigation and found that the Gen 4 vulnerability could allow a single affected device to serve as a gateway for accessing nearly all smart home devices, regardless of brand. With many European homes using mixed-generation networks that include both Shelly and other smart devices, this leaves a significant gap in overall security—both online and offline.
Shelly’s Response and User Actions
Shelly has been informed of the security gap, and the company claims that Firmware 1.8.0 will address this flaw. However, users are currently required to manually disable the access points themselves, which may not be something most homeowners are aware of.
Ken Munro, founder of Pen Test Partners, told Euronews Next that Shelly should launch a communication campaign to inform users about the open access point and how to deactivate it. He suggested that the company is avoiding such a move to protect its reputation.
Shelly responded by stating that users who follow the official setup methods through their mobile app automatically have the access point disabled. For those who opt for manual configuration, warnings are provided to secure the access point. An upcoming firmware update will also auto-disable access points after a timeout period.
“We would like to emphasize that all configuration flows and digital assets within the Shelly ecosystem— including our mobile app and web cloud interface— provide clear guidance to users on securing their devices,” a Shelly spokesperson said.
They added that any configuration choices made outside of these recommended workflows, including leaving the access point unsecured, are ultimately a matter of user preference and fall outside the scope of direct platform control.
Addressing the Broader Trend of Connected Device Vulnerabilities
This issue is part of a growing trend where vulnerabilities in connected devices have come under scrutiny. Other examples include Amazon’s Ring doorbells and Dahua security cameras. Ken Munro noted that his team tests various smart home systems and has encountered similar issues in solar inverters and even in cars over a decade ago.
Data leakage is another major concern. Smart home devices often collect usage and behavioral data, which can sometimes be accidentally leaked. Munro explained that manufacturers collect this data to improve their products, but they often overlook the potential value of individual data.
The Future of Smart Home Security
Shelly is planning to introduce an improvement that will automatically disable the access point after a predefined timeout, unless it is explicitly needed for configuration or provisioning. This update aims to enhance user security without compromising convenience.
As smart home technology continues to evolve, the need for robust cybersecurity measures becomes increasingly important. Users must remain vigilant and follow recommended security practices to protect their homes from potential threats.























