CPATH-2026-0033 · General IoT

Chirp Systems / Chirp Access smart-lock app hardcoded credentials (CVE-2024-2197)

Two or more co-dominant consequence paths connect the public security record to a provisional HIGH consequence band.

Candidate bandHIGH
Co-dominant pathsAccount authority + Device-control safety

These paths are co-dominant because each reaches the record's highest candidate band, HIGH; no array-order tie-break is applied.

Causal model

What has to happen for this consequence to hold?

2 candidate paths · explicit source, inference, and assumption boundaries.

Authority · Co-dominant path

Account authority

The credential reaches bounded beacon configuration functions; it does not grant fleet administration or a firmware-signing root.

HIGH
  1. accessSource-backed

    Reusable artifact or reachable service

    Anyone can download the Chirp Access app and extract its embedded static credential without touching a resident's device.

    EvidenceNVD

  2. boundaryModel inference

    Reusable multi-stage bridge

    A public app artifact yields a credential that crosses into deployed access-control beacon configuration.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Bounded function authority

    The credential reaches bounded beacon configuration functions; it does not grant fleet administration or a firmware-signing root.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Account authority

    The credential reaches bounded beacon configuration functions; it does not grant fleet administration or a firmware-signing root.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Fleet action or replacement

    The vendor must remove and rotate the embedded secret across the app and affected beacon population.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 3
Reusable artifact or reachable service

Anyone can download the Chirp Access app and extract its embedded static credential without touching a resident's device.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

The credential is stored in the app artifact, so extraction is a straightforward inspection task.

Source-backedNVD
ExposureEX 3
Access position limits exposure

The technique is easier to perform than it is to position against a target, so access is the constraining factor.

Model inference
Consequence
Physical / safetyPH 2
Operational safety effect

Beacon configuration can affect an access-control installation, but the confirmed evidence does not show remote door unlock or severe physical harm.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

The exposed value is a shared production credential for beacon and backend configuration functions.

Model inference
AuthorityAT 2
Bounded function authority

The credential reaches bounded beacon configuration functions; it does not grant fleet administration or a firmware-signing root.

Model inference
Scale and recovery
ChainabilityCH 3
Reusable multi-stage bridge

A public app artifact yields a credential that crosses into deployed access-control beacon configuration.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

The same embedded secret appears across app installations, so one extraction produces a portable credential.

Operational assumption
Execution scaleSX 3
Deployment-wide with setup

Knowledge of the secret is deployment-wide, while applying it to a beacon still requires local radio proximity.

Operational assumption
Recovery burdenOR 4
Fleet action or replacement

The vendor must remove and rotate the embedded secret across the app and affected beacon population.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Mitigated
Vendor mitigation is recorded

The record treats the path as mitigated; the historical mechanism remains useful for review and regression analysis.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandHIGH
  2. No adjustment

    The HIGH base band remains final because no separate cap or systemic uplift applies. The credential reaches bounded beacon configuration functions; it does not grant fleet administration or a firmware-signing root.

  3. Final candidate bandHIGH
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:3/EC:4/EX:3/PH:2/DP:3/AT:2/CH:3/SR:4/SX:3/OR:4/EV:2/LS:MITIGATEDRead the scoring method →

Safety · Co-dominant path

Device-control safety

The confirmed effect is bounded beacon reconfiguration; a reported remote-unlock claim was retracted and is not used here.

HIGH
  1. accessSource-backed

    Proximity or local access

    Changing an installed beacon requires BLE proximity even after the shared application credential is known.

    EvidenceNVD

  2. boundaryModel inference

    One cross-boundary bridge

    The embedded app credential crosses the BLE boundary into one deployed beacon.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Operational safety effect

    The confirmed effect is bounded beacon reconfiguration; a reported remote-unlock claim was retracted and is not used here.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Device-control safety

    The confirmed effect is bounded beacon reconfiguration; a reported remote-unlock claim was retracted and is not used here.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Fleet action or replacement

    The install base needs updated app or firmware material that removes and rotates the shared credential.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 2
Proximity or local access

Changing an installed beacon requires BLE proximity even after the shared application credential is known.

Source-backedNVD
Execution complexityEC 3
Reproducible exploit workflow

Once nearby, the attacker can use the recovered credential through the ordinary beacon-configuration workflow.

Source-backedNVD
ExposureEX 2
Access position limits exposure

The technique is easier to perform than it is to position against a target, so access is the constraining factor.

Model inference
Consequence
Physical / safetyPH 2
Operational safety effect

The confirmed effect is bounded beacon reconfiguration; a reported remote-unlock claim was retracted and is not used here.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

The path changes operational configuration of an access-control beacon rather than extracting resident data.

Model inference
AuthorityAT 2
Bounded function authority

Authority is limited to the exposed beacon settings and does not include lock commands, administrator control, or firmware signing.

Model inference
Scale and recovery
ChainabilityCH 2
One cross-boundary bridge

The embedded app credential crosses the BLE boundary into one deployed beacon.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

The same shared credential can be presented to any affected beacon.

Operational assumption
Execution scaleSX 2
Proximity-bound repetition

Each target beacon must be approached over BLE, so execution remains proximity-bound.

Operational assumption
Recovery burdenOR 4
Fleet action or replacement

The install base needs updated app or firmware material that removes and rotates the shared credential.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Mitigated
Vendor mitigation is recorded

The record treats the path as mitigated; the historical mechanism remains useful for review and regression analysis.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandHIGH
  2. No adjustment

    The HIGH base band remains final because no separate cap or systemic uplift applies. The confirmed effect is bounded beacon reconfiguration; a reported remote-unlock claim was retracted and is not used here.

  3. Final candidate bandHIGH
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:3/EX:2/PH:2/DP:3/AT:2/CH:2/SR:4/SX:2/OR:4/EV:2/LS:MITIGATEDRead the scoring method →

Triage implication

Verify the authority transition before acting on the band.

Validate the deployment-specific transition from digital control or perception to physical action before setting remediation urgency.

Evidence ledger

Public sources used by this record.

Every named source includes a public link. Path review remains separate from citation coverage.

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipPaths model is higher
Baseline confidencehigh
Scored2026-06-03
v4.0 · 2.3 LOWCISA/ICS-CERT via NVD
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
v3.1 · 4.3 MEDIUMCISA/ICS-CERT via NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

Assessment

CFSE Consequence Paths assesses Chirp Systems / Chirp Access smart-lock app hardcoded credentials (CVE-2024-2197) at HIGH — the worst of 2 risk paths (authority, safety). The dominant consequence is privileged account or control authority.

Vulnerability

Chirp Systems / Chirp Access smart-lock app hardcoded credentials (CVE-2024-2197). Reported attack vector: Adjacent (Bluetooth range, ~30m) per the revised NVD assessment; initial CISA claim alleged network/remote unlock but was retracted.

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

ACCOUNT_AUTHORITYHIGH

CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:3/EC:4/EX:3/PH:2/DP:3/AT:2/CH:3/SR:4/SX:3/OR:4/EV:2/LS:MITIGATED

Exposure EX=3 (reachability-bound) · bands PH=HIGH · DP=HIGH · AT=HIGH → base HIGH · uplift recall-class recovery → assessed HIGH.

Hardcoded BEACON_PASSWORD (CWE-259/798) is embedded in the public Chirp Access app; an attacker downloads the app and extracts the static credential (RE:3 own-artifact, not physical; EC:4 trivial). The secret is a shared credential authenticating to beacon/back-end functions (DP:3 credential/firmware-tier secret). Confirmed authority is bounded to beacon config functions, not admin/fleet control, so AT:2. SR:4: one secret shared across all installs, fully portable. SX:3: knowledge is deployment-wide but turning it into effect still needs proximity, so not true remote fleet-scale (not 4). CH:3 bridges app->credential->device-config boundary. OR:4: remediation requires app/firmware update to rotate the embedded secret across the install base and vendor was unresponsive. EV:2 report-backed.

DEVICE_CONTROL_SAFETYHIGH

CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:3/EX:2/PH:2/DP:3/AT:2/CH:2/SR:4/SX:2/OR:4/EV:2/LS:MITIGATED

Exposure EX=2 (reachability-bound) · bands PH=ELEVATED · DP=HIGH · AT=ELEVATED → base HIGH · uplift recall-class recovery → assessed HIGH.

  • Confirmed consequence per revised NVD/CISA (CVSS AV:A, I:L): an attacker within Bluetooth range (~30m) uses the hardcoded credential to modify Bluetooth beacon configuration, e.g. disabling proximity-unlock notifications on a smart-lock/keyless-entry system. RE:2 BLE/proximity. EC:3 standard once positioned. AT:2 bounded config control of one beacon, not lock-command/admin authority (the disputed remote-unlock claim was retracted, so not AT:3+/PH:4). PH:2: degrades a physical access-control convenience feature / availability of proximity unlock, no confirmed severe harm.
  • perception_feeds_action — false: beacon config change does not drive a safety-relevant actuation in the confirmed scope. DP:3 config/operational integrity of an access-control device. SR:4 same shared secret enables this on any install. SX:2 per-device proximity needed. CH:2 crosses app->BLE->device boundary. OR:4 fix requires fleet-wide app/firmware update; vendor unresponsive. EV:2 report-backed; disputed higher-impact unlock scenario excluded to avoid inflation.

Published baseline

  • v4.0 2.3 LOW — CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X — CISA/ICS-CERT via NVD
  • v3.1 4.3 MEDIUM — CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N — CISA/ICS-CERT via NVD

The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.

Sources

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0033 (“Chirp Systems / Chirp Access smart-lock app hardcoded credentials (CVE-2024-2197)”), paths.cfse.ai/CPATH-2026-0033 (published 2026-06-03).