Research study
Smart garage openers and the security question
Twenty publicly documented flaws across four connected openers, from records anyone can check, with how each maker actually responded.
Written by HyreGarage Research Desk Primary-source research and security-disclosure review
Audited by HyreGarage Research Desk Citation, CVE verification and retrieval-date audit
The finding
We found 20 publicly disclosed security flaws (CVEs) across four smart garage opener platforms in the National Vulnerability Database. How makers responded varied. Chamberlain fixed its myQ flaw within 10 days.
Genie patched two of three. Nexx never replied: CISA advisory ICSA-23-094-01 says Nexx “has not responded to requests to work with CISA.” Records retrieved 2026-09-06.
What did we find?
Every flaw here has a CVE number (a public ID for a known security flaw) in the National Vulnerability Database. We found 20 across four platforms: iSmartgate PRO (11 CVEs, 2020), Nexx Smart Home (5, 2023), Genie Aladdin Connect (3, 2023-2024) and Chamberlain myQ (1, 2023).
Chamberlain fixed its myQ password-reset flaw on its servers within 10 days of being told. Genie/Overhead Door patched two of three Aladdin Connect flaws in a coordinated disclosure with Rapid7, with a documented workaround for the third.
CISA’s advisory ICSA-23-094-01 says: “Nexx has not responded to requests to work with CISA to mitigate these vulnerabilities.” No patch existed at publication for any of Nexx’s five flaws. One was a Critical hard-coded password issue scored 9.3.
iSmartgate’s 11 CVEs date from a 2020 academic disclosure. We found no version-specific patch confirmation for that set.
What is this page, and what isn’t it?
Read this before the CVE tables below.
Every CVE, score and timeline here is already public in the National Vulnerability Database, a CISA advisory, or a named researcher’s own writeup. We link to the source for every claim. We do not describe how to reproduce anything.
Two of the four makers responded quickly and patched. The story is uneven maker response, not a blanket charge against connected garage technology.
CISA, Rapid7 and the original researchers named these products in their own public advisories. We report what they published. We are not making a new accusation.
Any maker named here, Nexx included, can send documented evidence of a patch or status change through HyreGarage’s normal editorial contact channel. We will correct this page promptly.
Check your app or firmware version against the maker’s own patch notes. Several of these flaws were fixed years ago. We report the disclosure and patch history, not current live exposure.
Everything comes from published records. HyreGarage did not try to access, reproduce or verify any of these flaws on a live product.
Which smart opener flaws are the most severe?
Chamberlain’s myQ account takeover (9.8) and Nexx’s hard-coded credentials (9.3), both Critical. Here are the nine flaws NVD scored individually, highest first.
| CVE | Platform | CVSS | Severity | What it does |
|---|---|---|---|---|
| CVE-2023-24080 | Chamberlain myQ | 9.8 | Critical | No rate limiting on the password-reset endpoint allows account takeover by brute force. |
| CVE-2023-1748 | Nexx Smart Home | 9.3 | Critical | Hard-coded credentials expose the MQTT server, allowing remote control of any connected device. |
| CVE-2023-5880 | Genie Aladdin Connect | 8.8 | High | Unauthenticated access to the setup web interface while the device is in configuration mode. |
| CVE-2023-5881 | Genie Aladdin Connect | 8.2 | High | The Garage Door Control Module setup page allows unauthenticated Wi-Fi reconfiguration on the local network. |
| CVE-2023-1752 | Nexx Smart Home | 8.1 | High | Improper authentication allows registering an already-registered device using only its MAC address. |
| CVE-2023-1751 | Nexx Smart Home | 7.5 | High | WebSocket server fails to validate bearer tokens, leaking alarm data across devices. |
| CVE-2023-1750 | Nexx Smart Home | 7.1 | High | Authorization bypass via a user-controlled key allows retrieving device history and settings with a valid device ID. |
| CVE-2023-5879 | Genie Aladdin Connect | 6.8 | Medium | Account credentials stored in cleartext in the Android app’s shared preferences file. |
| CVE-2023-1749 | Nexx Smart Home | 6.5 | Medium | Authorization bypass allows unauthorized API execution using a valid device ID. |
CVSS (a standard 0-10 severity score) v3.1 base scores, as published by the National Vulnerability Database. Descriptions are HyreGarage paraphrases of NVD’s official description, not its exact wording.
What were the eleven iSmartgate PRO flaws?
Web-interface flaws disclosed in 2020, three years before the others. NVD did not score them individually in the records we retrieved.
Origin
These eleven CVEs trace to a 2020 academic disclosure. NVD cites a KTH Royal Institute of Technology thesis as the third-party advisory. All affect iSmartgate PRO version 1.5.9.
They cover cross-site request forgery (tricking a logged-in browser into sending commands) that allows remote door open/close, privilege escalation via appended PHP code, malicious file upload, and clickjacking.
The list
CVE-2020-12280 (CSRF, remote door open/close); CVE-2020-12281 (CSRF, create new user); CVE-2020-12282 (CSRF, user search); CVE-2020-12837 (malicious image upload); CVE-2020-12838 (privilege escalation); CVE-2020-12839 (privilege escalation); CVE-2020-12840 (CSRF, sound file upload); CVE-2020-12841 (CSRF, image file upload); CVE-2020-12842 (privilege escalation); CVE-2020-12843 (malicious sound upload); CVE-2020-13119 (clickjacking).
Patch status
NVD’s record cites iSmartgate’s own product page as a “Vendor Advisory” reference. That page, as published now, does not confirm a fix for this exact 2020 set by version. We report it as unconfirmed rather than assume a fix or its absence.
How did each maker respond?
Two patched, one did not respond, one is unconfirmed. This is the part of the page most worth reading.
| Vendor / product | CVEs | Reported | Resolved | Outcome |
|---|---|---|---|---|
| Chamberlain (myQ) | 1 | January 10, 2023 | January 20, 2023 | Patched — server-side rate limiting deployed within 10 days. |
| Genie / Overhead Door (Aladdin Connect) | 3 | August 22, 2023 | App v5.73 (Sept. 2023); firmware v14.1.1 (Dec. 2023); API fix July 25, 2023 | Two of three patched; third rated low-impact with a configuration workaround (use the app, not the local web interface). |
| Nexx Smart Home | 5 | Per CISA advisory, 2023 | None recorded | Unpatched at advisory publication. CISA states Nexx "has not responded to requests to work with CISA to mitigate these vulnerabilities." |
| iSmartgate | 11 | 2020 (academic disclosure) | Not confirmed | No public patch confirmation found for this specific set of 2020 CVEs as of retrieval. |
Reported and resolved dates are as stated in each disclosure’s own source (CISA advisory, Rapid7 blog, or the original researcher’s post). They are not HyreGarage estimates.
The difference between makers is the real story
A list of 20 CVEs first looks like proof that connected openers are broadly insecure. The records tell a more specific, more useful story.
Chamberlain’s myQ password-reset flaw was Critical, scored 9.8. It could let an attacker guess their way into any account. It was reported on January 10, 2023 and fixed on Chamberlain’s servers within ten days, with no app update needed. That is a fast, competent response.
Genie/Overhead Door took longer with Aladdin Connect. Rapid7 reported in August 2023, and fixes rolled out through December. But the maker engaged throughout and fixed two of three issues. For the third, which it rated low-impact, it gave a documented workaround: use the mobile app, not the local web interface.
Nexx is the outlier, and a federal agency says so, not us. CISA’s advisory states the maker did not engage with a coordinated disclosure attempt. No fix existed for any of its five flaws, including a Critical hard-coded-credential issue, when the advisory was published.
HyreGarage analysis: the lesson is not “avoid smart openers.” It is that a maker’s record of handling flaw reports is useful to know before you buy. In Nexx’s case, that record is documented as poor by the U.S. government’s own cybersecurity advisory system.
A standard opener with no connection has no comparable attack surface: no app, no cloud account and no Wi-Fi setup page to misconfigure. A connected opener trades that for real conveniences, such as remote monitoring, guest access codes and smart-home links.
These four cases suggest the trade is reasonable with a maker that takes flaw reports seriously. It is far less reasonable with one that does not answer when a federal agency calls. For an older kind of opener security flaw, see how fixed-code remotes were replaced by rolling codes.
What do the security terms mean?
- CVE
- Common Vulnerabilities and Exposures: a unique public ID for a specific, documented security flaw. MITRE maintains it, and NVD catalogs the details.
- CVSS
- Common Vulnerability Scoring System: a standard 0-10 severity score. We report CVSS v3.1 base scores as published by NVD, not our own assessment.
- CISA advisory
- A public bulletin from the U.S. Cybersecurity and Infrastructure Security Agency, usually issued after it coordinates (or tries to coordinate) disclosure with the affected maker.
- Coordinated disclosure
- Privately telling a maker about a flaw and giving it time to patch before going public. Genie/Overhead Door and Chamberlain both acted on this kind of report. CISA’s advisory states Nexx did not engage.
- Responsible disclosure timeline
- The dates between a flaw being reported to a maker and a fix being confirmed, as stated in each disclosure’s own source.
What should you check before buying a smart garage opener?
Five minutes on the maker’s own site and a public database, before you buy.
NVD’s own search (nvd.nist.gov) is free and public. A brand with past disclosures is not automatically worse than one with none. It may just mean no researcher has looked, or the company publishes no disclosure policy.
Makers that invite researchers to report issues, as CISA and every disclosure here recommend, tend to have a checkable patch history. Others force researchers to go through a federal agency just to reach them.
A companion app not updated in over a year is a weak signal alone. Combined with no published disclosure policy, it is worth weighing before you buy.
Every fix on this page shipped as an app or firmware update. A patch only protects a device running the patched version. Our opener selector covers the other choices, and our opener guide covers repair and replacement.
What couldn’t we confirm?
A confirmed patch status for the 2020 iSmartgate PRO CVEs. NVD cites the maker’s current product page, but it has no version-specific statement about these eleven 2020 flaws. We report this as unconfirmed rather than guess.
Any flaw we found ourselves. Every item here traces to an already-published CVE, CISA advisory or researcher disclosure. We did not test, scan or try to access any live product. We publish nothing that would help anyone reproduce these issues.
Whether any flaw was exploited in the wild. The disclosures document each flaw and its severity. None of the sources we read claimed evidence of active exploitation, and we make no such claim.
A complete list of every connected opener CVE ever assigned. We reviewed the records our keyword and vendor searches found on the retrieval date. A broader or later search could find more disclosures than are listed here.
Questions
Is it safe to use a smart garage door opener?
What is the CVE for the Chamberlain myQ vulnerability?
Did Nexx patch its garage controller vulnerabilities?
What vulnerabilities were found in the Genie Aladdin Connect opener?
How many garage door opener vulnerabilities have been publicly disclosed?
Does this page explain how to hack a garage door opener?
How can I check if my opener model has a known vulnerability?
What should a maker’s response to a vulnerability report look like?
Written and audited by
HyreGarage Research Desk
Primary-source research, data analysis and fact checking
We are not a garage door company. We read the agency file, the code record, the standards document or the public register ourselves, compute the figure from it, and publish it with the source and the date we retrieved it.
Where a number cannot be traced to a primary source, we publish the shorter page and say what we could not verify. Our own company records cover ten states; nothing national is ever derived from them.
- 10
- states our own company records cover — and the limit of any claim made from them
- 3,901
- garage door companies in the store
- 457
- license records verified against a state board
- 0
- national claims made from a ten-state store
How this desk works
- Primary sources only. Injury counts come from CPSC. Housing counts come from the Census file, not from a summary of it. Code history comes from the building commission that adopted the code. We do not cite an article that cites a source; we retrieve the source and do the arithmetic ourselves.
- Every figure carries its retrieval date. Registers change, datasets are revised and codes are amended. A number without the date it was read cannot be checked, so every study states one.
- Fact, calculation and analysis are labeled apart. A quote is a quote, a HyreGarage computation says so, and an interpretation says “HyreGarage analysis”. Presenting our reading of a dataset as something the agency stated would be the easiest way to lose the only thing this desk is for.
- Limitations go above the fold. If a figure is an upper bound, a bracket, or an association rather than a cause, that is said before the figure is quoted rather than in a footnote underneath it.
- No DIY instructions for spring, cable or track work. Those components hold enough stored energy to cause serious injury, and CPSC records the consequences. We describe what has failed and what a competent repair involves; we do not tell you how to do it.
Data as of NVD CVE records and CISA advisory ICSA-23-094-01, retrieved 2026-09-06. Authorship on this site is organizational: the analysis belongs to the desk rather than to a named individual, and we do not publish credentials we do not hold. Our editorial policy sets out how we source, date and correct what we publish.
Sources & retrieval dates
Choosing between a smart and a standard opener?
Ask any smart-opener maker about its vulnerability disclosure and patch history before you buy. It is now a documented, checkable track record.
Find a Garage Door Professional Open the opener selector tool
HyreGarage is not a garage door company, a cybersecurity firm or a penetration-testing service, and does not perform, supervise or warrant garage door or IoT security work.
This page reports already-public vulnerability disclosures and the makers’ documented responses. It publishes no exploit code and makes no claim about any product’s current live security.
Named makers may request a correction through HyreGarage’s standard editorial contact channel.