HyreGarage

Research study

Smart garage openers and the security question

Twenty publicly documented flaws across four connected openers, from records anyone can check, with how each maker actually responded.

Updated September 2026 · Data as of NVD CVE records and CISA advisory ICSA-23-094-01, retrieved 2026-09-06

Written by HyreGarage Research Desk Primary-source research and security-disclosure review

Audited by HyreGarage Research Desk Citation, CVE verification and retrieval-date audit

20 publicly disclosed CVEs across four connected garage opener platforms NVD public API, retrieved 2026-09-06.
9.8 highest CVSS score found: Chamberlain myQ account takeover (CVE-2023-24080), patched within 10 days NVD CVSS v3.1 base score, retrieved 2026-09-06.
1 of 4 vendors did not respond to a federal cybersecurity agency’s coordinated disclosure attempt CISA advisory ICSA-23-094-01.

The finding

We found 20 publicly disclosed security flaws (CVEs) across four smart garage opener platforms in the National Vulnerability Database. How makers responded varied. Chamberlain fixed its myQ flaw within 10 days.

Genie patched two of three. Nexx never replied: CISA advisory ICSA-23-094-01 says Nexx “has not responded to requests to work with CISA.” Records retrieved 2026-09-06.

What did we find?

This reviews what is already public. It is not a new disclosure.

Every flaw here has a CVE number (a public ID for a known security flaw) in the National Vulnerability Database. We found 20 across four platforms: iSmartgate PRO (11 CVEs, 2020), Nexx Smart Home (5, 2023), Genie Aladdin Connect (3, 2023-2024) and Chamberlain myQ (1, 2023).

Makers did not all respond the same way.

Chamberlain fixed its myQ password-reset flaw on its servers within 10 days of being told. Genie/Overhead Door patched two of three Aladdin Connect flaws in a coordinated disclosure with Rapid7, with a documented workaround for the third.

One maker did not respond at all. That finding is CISA’s, not ours.

CISA’s advisory ICSA-23-094-01 says: “Nexx has not responded to requests to work with CISA to mitigate these vulnerabilities.” No patch existed at publication for any of Nexx’s five flaws. One was a Critical hard-coded password issue scored 9.3.

For the fourth maker, we could not confirm a patch either way.

iSmartgate’s 11 CVEs date from a 2020 academic disclosure. We found no version-specific patch confirmation for that set.

What is this page, and what isn’t it?

Read this before the CVE tables below.

Nothing here is new, and nothing here is exploit code.

Every CVE, score and timeline here is already public in the National Vulnerability Database, a CISA advisory, or a named researcher’s own writeup. We link to the source for every claim. We do not describe how to reproduce anything.

This does not claim smart openers are broadly unsafe.

Two of the four makers responded quickly and patched. The story is uneven maker response, not a blanket charge against connected garage technology.

We name makers and products because the disclosures already do.

CISA, Rapid7 and the original researchers named these products in their own public advisories. We report what they published. We are not making a new accusation.

Right of reply.

Any maker named here, Nexx included, can send documented evidence of a patch or status change through HyreGarage’s normal editorial contact channel. We will correct this page promptly.

A CVE does not mean your device is vulnerable today.

Check your app or firmware version against the maker’s own patch notes. Several of these flaws were fixed years ago. We report the disclosure and patch history, not current live exposure.

We did not test, scan or probe any device.

Everything comes from published records. HyreGarage did not try to access, reproduce or verify any of these flaws on a live product.

Which smart opener flaws are the most severe?

Chamberlain’s myQ account takeover (9.8) and Nexx’s hard-coded credentials (9.3), both Critical. Here are the nine flaws NVD scored individually, highest first.

CVSS severity distribution, 9 scored CVEs across three platformsCVSS v3.1 severity among the 9 individually scored CVEs affecting Nexx Smart Home, Chamberlain myQ and Genie Aladdin Connect examined on this page: 2 Critical, 5 High, 2 Medium.Critical (9.0-10.0)2High (7.0-8.9)5Medium (4.0-6.9)2The 11 iSmartgate CVEs (2020) are listed separately and are not individually CVSS-scored in the NVD records we retrieved.CVSS severity distribution, 9 scored CVEs across three platformsCVSS v3.1 severity among the 9 individually scored CVEs affecting Nexx Smart Home, Chamberlain myQ and Genie Aladdin Connect examined on this page: 2 Critical, 5 High, 2 Medium.Critical (9.0-10.0)2High (7.0-8.9)5Medium (4.0-6.9)2The 11 iSmartgate CVEs (2020) are listedseparately and are not individually CVSS-scored in the NVD records we retrieved.
CVSS v3.1 severity among the nine scored flaws: 2 Critical, 5 High, 2 Medium, across three platforms. The fourth, iSmartgate, is listed separately below. HyreGarage tabulation of NVD CVE records, retrieved 2026-09-06.
CVEPlatformCVSSSeverityWhat it does
CVE-2023-24080Chamberlain myQ9.8CriticalNo rate limiting on the password-reset endpoint allows account takeover by brute force.
CVE-2023-1748Nexx Smart Home9.3CriticalHard-coded credentials expose the MQTT server, allowing remote control of any connected device.
CVE-2023-5880Genie Aladdin Connect8.8HighUnauthenticated access to the setup web interface while the device is in configuration mode.
CVE-2023-5881Genie Aladdin Connect8.2HighThe Garage Door Control Module setup page allows unauthenticated Wi-Fi reconfiguration on the local network.
CVE-2023-1752Nexx Smart Home8.1HighImproper authentication allows registering an already-registered device using only its MAC address.
CVE-2023-1751Nexx Smart Home7.5HighWebSocket server fails to validate bearer tokens, leaking alarm data across devices.
CVE-2023-1750Nexx Smart Home7.1HighAuthorization bypass via a user-controlled key allows retrieving device history and settings with a valid device ID.
CVE-2023-5879Genie Aladdin Connect6.8MediumAccount credentials stored in cleartext in the Android app’s shared preferences file.
CVE-2023-1749Nexx Smart Home6.5MediumAuthorization bypass allows unauthorized API execution using a valid device ID.

CVSS (a standard 0-10 severity score) v3.1 base scores, as published by the National Vulnerability Database. Descriptions are HyreGarage paraphrases of NVD’s official description, not its exact wording.

What were the eleven iSmartgate PRO flaws?

Web-interface flaws disclosed in 2020, three years before the others. NVD did not score them individually in the records we retrieved.

Origin

These eleven CVEs trace to a 2020 academic disclosure. NVD cites a KTH Royal Institute of Technology thesis as the third-party advisory. All affect iSmartgate PRO version 1.5.9.

They cover cross-site request forgery (tricking a logged-in browser into sending commands) that allows remote door open/close, privilege escalation via appended PHP code, malicious file upload, and clickjacking.

The list

CVE-2020-12280 (CSRF, remote door open/close); CVE-2020-12281 (CSRF, create new user); CVE-2020-12282 (CSRF, user search); CVE-2020-12837 (malicious image upload); CVE-2020-12838 (privilege escalation); CVE-2020-12839 (privilege escalation); CVE-2020-12840 (CSRF, sound file upload); CVE-2020-12841 (CSRF, image file upload); CVE-2020-12842 (privilege escalation); CVE-2020-12843 (malicious sound upload); CVE-2020-13119 (clickjacking).

Patch status

NVD’s record cites iSmartgate’s own product page as a “Vendor Advisory” reference. That page, as published now, does not confirm a fix for this exact 2020 set by version. We report it as unconfirmed rather than assume a fix or its absence.

How did each maker respond?

Two patched, one did not respond, one is unconfirmed. This is the part of the page most worth reading.

Vendor / productCVEsReportedResolvedOutcome
Chamberlain (myQ)1January 10, 2023January 20, 2023Patched — server-side rate limiting deployed within 10 days.
Genie / Overhead Door (Aladdin Connect)3August 22, 2023App v5.73 (Sept. 2023); firmware v14.1.1 (Dec. 2023); API fix July 25, 2023Two of three patched; third rated low-impact with a configuration workaround (use the app, not the local web interface).
Nexx Smart Home5Per CISA advisory, 2023None recordedUnpatched at advisory publication. CISA states Nexx "has not responded to requests to work with CISA to mitigate these vulnerabilities."
iSmartgate112020 (academic disclosure)Not confirmedNo public patch confirmation found for this specific set of 2020 CVEs as of retrieval.

Reported and resolved dates are as stated in each disclosure’s own source (CISA advisory, Rapid7 blog, or the original researcher’s post). They are not HyreGarage estimates.

The difference between makers is the real story

A list of 20 CVEs first looks like proof that connected openers are broadly insecure. The records tell a more specific, more useful story.

Chamberlain’s myQ password-reset flaw was Critical, scored 9.8. It could let an attacker guess their way into any account. It was reported on January 10, 2023 and fixed on Chamberlain’s servers within ten days, with no app update needed. That is a fast, competent response.

Genie/Overhead Door took longer with Aladdin Connect. Rapid7 reported in August 2023, and fixes rolled out through December. But the maker engaged throughout and fixed two of three issues. For the third, which it rated low-impact, it gave a documented workaround: use the mobile app, not the local web interface.

Nexx is the outlier, and a federal agency says so, not us. CISA’s advisory states the maker did not engage with a coordinated disclosure attempt. No fix existed for any of its five flaws, including a Critical hard-coded-credential issue, when the advisory was published.

HyreGarage analysis: the lesson is not “avoid smart openers.” It is that a maker’s record of handling flaw reports is useful to know before you buy. In Nexx’s case, that record is documented as poor by the U.S. government’s own cybersecurity advisory system.

A standard opener with no connection has no comparable attack surface: no app, no cloud account and no Wi-Fi setup page to misconfigure. A connected opener trades that for real conveniences, such as remote monitoring, guest access codes and smart-home links.

These four cases suggest the trade is reasonable with a maker that takes flaw reports seriously. It is far less reasonable with one that does not answer when a federal agency calls. For an older kind of opener security flaw, see how fixed-code remotes were replaced by rolling codes.

What do the security terms mean?

CVE
Common Vulnerabilities and Exposures: a unique public ID for a specific, documented security flaw. MITRE maintains it, and NVD catalogs the details.
CVSS
Common Vulnerability Scoring System: a standard 0-10 severity score. We report CVSS v3.1 base scores as published by NVD, not our own assessment.
CISA advisory
A public bulletin from the U.S. Cybersecurity and Infrastructure Security Agency, usually issued after it coordinates (or tries to coordinate) disclosure with the affected maker.
Coordinated disclosure
Privately telling a maker about a flaw and giving it time to patch before going public. Genie/Overhead Door and Chamberlain both acted on this kind of report. CISA’s advisory states Nexx did not engage.
Responsible disclosure timeline
The dates between a flaw being reported to a maker and a fix being confirmed, as stated in each disclosure’s own source.

What should you check before buying a smart garage opener?

Five minutes on the maker’s own site and a public database, before you buy.

01
Search the brand name plus “CVE” or “vulnerability”

NVD’s own search (nvd.nist.gov) is free and public. A brand with past disclosures is not automatically worse than one with none. It may just mean no researcher has looked, or the company publishes no disclosure policy.

02
Look for a published vulnerability disclosure or bug bounty program

Makers that invite researchers to report issues, as CISA and every disclosure here recommend, tend to have a checkable patch history. Others force researchers to go through a federal agency just to reach them.

03
Check the app store listing’s last update date

A companion app not updated in over a year is a weak signal alone. Combined with no published disclosure policy, it is worth weighing before you buy.

04
Keep the app and firmware current after you buy

Every fix on this page shipped as an app or firmware update. A patch only protects a device running the patched version. Our opener selector covers the other choices, and our opener guide covers repair and replacement.

What couldn’t we confirm?

A confirmed patch status for the 2020 iSmartgate PRO CVEs. NVD cites the maker’s current product page, but it has no version-specific statement about these eleven 2020 flaws. We report this as unconfirmed rather than guess.

Any flaw we found ourselves. Every item here traces to an already-published CVE, CISA advisory or researcher disclosure. We did not test, scan or try to access any live product. We publish nothing that would help anyone reproduce these issues.

Whether any flaw was exploited in the wild. The disclosures document each flaw and its severity. None of the sources we read claimed evidence of active exploitation, and we make no such claim.

A complete list of every connected opener CVE ever assigned. We reviewed the records our keyword and vendor searches found on the retrieval date. A broader or later search could find more disclosures than are listed here.

Questions

Is it safe to use a smart garage door opener?
It depends on the maker. Chamberlain and Genie/Overhead Door responded quickly to serious flaw reports and patched. Nexx, per CISA’s advisory, did not respond and had no patch for five documented flaws at publication. Check your own product’s patch history and keep its app and firmware updated.
What is the CVE for the Chamberlain myQ vulnerability?
CVE-2023-24080. The password-reset page had no limit on attempts, so an attacker could guess their way into an account. NVD scored it 9.8 (Critical). It was reported to Chamberlain on January 10, 2023 and fixed with server-side rate limiting by January 20, 2023.
Did Nexx patch its garage controller vulnerabilities?
Not as of CISA’s advisory ICSA-23-094-01, which states: “Nexx has not responded to requests to work with CISA to mitigate these vulnerabilities.” It documented five CVEs, including a Critical hard-coded credential flaw (CVE-2023-1748, CVSS 9.3). We report the record at retrieval and welcome a documented update from Nexx.
What vulnerabilities were found in the Genie Aladdin Connect opener?
Three, documented by Rapid7: passwords stored in plain text in the Android app (CVE-2023-5879, fixed by app update); open access to the setup page in configuration mode (CVE-2023-5880, fixed by firmware); and Wi-Fi reconfiguration through the local setup page (CVE-2023-5881, rated low-impact, with a workaround).
How many garage door opener vulnerabilities have been publicly disclosed?
20 CVEs across four connected platforms in our review: iSmartgate PRO (11, from 2020), Nexx Smart Home (5), Genie Aladdin Connect (3) and Chamberlain myQ (1). This reflects our keyword and vendor searches on the retrieval date, not necessarily every disclosure ever made.
Does this page explain how to hack a garage door opener?
No. Every claim here is a documented fact from a public record: a CVE ID, a CVSS score, a disclosure date or a maker’s response. We publish no exploit code, no proof-of-concept, and nothing that would help anyone reproduce these flaws.
How can I check if my opener model has a known vulnerability?
Search the National Vulnerability Database (nvd.nist.gov) for your brand name. Then check your maker’s own security or support page for advisories. This page covers the four platforms we reviewed. It is not a complete registry of every connected opener flaw.
What should a maker’s response to a vulnerability report look like?
Acknowledge the report, give a timeline, and ship a fix through a normal software or firmware update. Chamberlain and Genie/Overhead Door did that within weeks to a few months. CISA’s Nexx advisory shows the alternative: no acknowledgment and no fix at publication.

Written and audited by

HyreGarage Research Desk

Primary-source research, data analysis and fact checking

We are not a garage door company. We read the agency file, the code record, the standards document or the public register ourselves, compute the figure from it, and publish it with the source and the date we retrieved it.

Where a number cannot be traced to a primary source, we publish the shorter page and say what we could not verify. Our own company records cover ten states; nothing national is ever derived from them.

10
states our own company records cover — and the limit of any claim made from them
3,901
garage door companies in the store
457
license records verified against a state board
0
national claims made from a ten-state store

How this desk works

  • Primary sources only. Injury counts come from CPSC. Housing counts come from the Census file, not from a summary of it. Code history comes from the building commission that adopted the code. We do not cite an article that cites a source; we retrieve the source and do the arithmetic ourselves.
  • Every figure carries its retrieval date. Registers change, datasets are revised and codes are amended. A number without the date it was read cannot be checked, so every study states one.
  • Fact, calculation and analysis are labeled apart. A quote is a quote, a HyreGarage computation says so, and an interpretation says “HyreGarage analysis”. Presenting our reading of a dataset as something the agency stated would be the easiest way to lose the only thing this desk is for.
  • Limitations go above the fold. If a figure is an upper bound, a bracket, or an association rather than a cause, that is said before the figure is quoted rather than in a footnote underneath it.
  • No DIY instructions for spring, cable or track work. Those components hold enough stored energy to cause serious injury, and CPSC records the consequences. We describe what has failed and what a competent repair involves; we do not tell you how to do it.

Data as of NVD CVE records and CISA advisory ICSA-23-094-01, retrieved 2026-09-06. Authorship on this site is organizational: the analysis belongs to the desk rather than to a named individual, and we do not publish credentials we do not hold. Our editorial policy sets out how we source, date and correct what we publish.

Sources & retrieval dates

National Vulnerability Database (NIST NVD): CVE records, Retrieved directly via the public NVD API (services.nvd.nist.gov/rest/json/cves/2.0) using keyword and vendor-name searches. Source of every CVE ID, CVSS v3.1 base score and official description on this page. Retrieved 2026-09-06.
CISA: ICS Advisory ICSA-23-094-01 (Nexx Smart Home Devices), Retrieved directly from cisa.gov. Source of the five Nexx CVEs, their CVSS scores, and the quoted statement that Nexx did not respond to CISA’s coordinated disclosure attempt. Retrieved 2026-09-06.
Rapid7: Genie Aladdin Connect Retrofit Garage Door Opener: Multiple Vulnerabilities, Retrieved directly from rapid7.com. Source of the three Aladdin Connect CVEs, the disclosure timeline (first report August 22, 2023, public disclosure January 3, 2024), and the maker’s patch and workaround details. Retrieved 2026-09-06.
Brackish Security: “Chamberlain myQ Account Takeover”, Original disclosure post, retrieved via an Internet Archive Wayback Machine snapshot (the live site did not respond to us). Source of the reported (January 10, 2023) and resolved (January 20, 2023) dates for CVE-2023-24080. Retrieved 2026-09-06.

Choosing between a smart and a standard opener?

Ask any smart-opener maker about its vulnerability disclosure and patch history before you buy. It is now a documented, checkable track record.

Find a Garage Door Professional Open the opener selector tool

HyreGarage is not a garage door company, a cybersecurity firm or a penetration-testing service, and does not perform, supervise or warrant garage door or IoT security work.

This page reports already-public vulnerability disclosures and the makers’ documented responses. It publishes no exploit code and makes no claim about any product’s current live security.

Named makers may request a correction through HyreGarage’s standard editorial contact channel.