Researchers identified critical denial-of-service vulnerabilities in Shelly Pro smart devices used for home automation and industrial control. In the Shelly Pro 4PM, an attacker can send an oversized request through the device's remote-control interface, causing it to reboot and potentially locking users out of their smart homes or disabling connected circuits. This vulnerability affects 30 API methods and can be exploited repeatedly without special privileges, impacting the reliability of smart home and building systems.
A separate but similar vulnerability was discovered in the Shelly Pro 3EM, where a specially crafted Modbus request can trigger an out-of-bounds read, forcing the device to reboot and resulting in a denial-of-service condition. Both vulnerabilities were reported by Nozomi Networks, and the Pro 3EM issue has been assigned CVE-2025-12056 with a CVSS v4 score of 8.3. Shelly has not responded to coordination attempts, and users are advised to minimize network exposure and implement defensive measures to reduce the risk of exploitation.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
The Shelly Pro 3EM vulnerability CVE-2025-12056 was subsequently listed in public CVE tracking feeds, reflecting broader public indexing of the issue after the CISA advisory.
In its advisory, CISA stated that Shelly did not respond to coordination attempts regarding CVE-2025-12056. CISA recommended standard ICS mitigations such as minimizing exposure, network segmentation, and VPN use, and noted no known public exploitation at publication.
CISA issued ICS advisory ICSA-25-322-03 for an out-of-bounds read vulnerability in Shelly Pro 3EM devices, tracked as CVE-2025-12056. A specially crafted Modbus request can force a reboot and cause a denial-of-service condition across all versions of the product.
Nozomi Networks Labs publicly disclosed CVE-2025-11243, explaining that the flaw can be reached over HTTP, WebSocket, and MQTT across multiple RPC methods. It recommended updating to firmware 1.6.0 or later and restricting access to web and RPC interfaces to trusted networks or VPNs.
A denial-of-service vulnerability in the Shelly Pro 4PM smart relay was identified in firmware version 1.4.4. Oversized JSON-RPC input can trigger unbounded memory allocation during parsing, causing repeated reboots and loss of device availability before authentication.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcenozominetworks.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.