
YES and not just the bulb. The Philips Hue chain: Check Point researchers discovered CVE-2020-6007 in Philips Hue bulbs. An attacker floods the bulb with signals making it flicker. the user notices the malfunction and deletes it from the app. then adds it back. the bulb re-joins the Zigbee network carrying malware in its firmware. the malware sends a flood of data to the Hue bridge, triggering a buffer overflow. the bridge installs the malware. the bridge connects to your router. the attacker is now inside your network. The TP-Link Tapo L530E: Universities in the UK and Italy found four vulnerabilities in the bestselling smart bulb on Amazon Italy. two rated High severity. an attacker nearby could impersonate the bulb during setup and steal your WiFi password from the Tapo app in plaintext. the attack requires no authentication and no interaction from the victim beyond the initial setup. Shodan lists millions of IoT devices publicly accessible with no authentication. smart bulbs are discoverable by model and firmware version. once a known CVE exists for that firmware, attackers scan, find, and exploit at scale. What to do: — keep firmware updated. bulb manufacturers do release patches but rarely notify users. — put smart bulbs on a separate IoT network or VLAN. they don't need access to your laptop. — if your bulb brand has had a publicised CVE and no patch exists: replace it or isolate it.
