Vulnerabilities · 111 days ago
The Wall Display cannot keep its temperature feature without also keeping a control channel open. That breaks the usual fix of turning off the risky service, because on this model Bluetooth is part of the advertised function and RPC rides with it.
Pen Test Partners found RPC exposed over unprotected Bluetooth by default on the Shelly Wall Display. Shelly has now released firmware 2.6.2 to close it, and the issue affects the Wall Display, with the same Bluetooth design pattern extending across Shelly’s modern device line.
A nearby attacker could reconfigure the device and join it to an attacker-controlled network, which turns a wall-mounted convenience device into a foothold on the home or small-office network. The design trap matters beyond this one model: bundled sensors that depend on a management channel can leave no clean way to shut the control plane off.
1 source covering this story
Shelly Wall Display exposed RPC over Bluetooth | Pen Test Partners
While I was investigating that, I started looking more broadly at the Bluetooth configuration across Shelly’s modern device range and found another issue, this time with the Wall Display.
Part of the PlainSec briefing for 2026-05-26