← Registry

CPATH-2026-0034 · GENERAL IOT

August Smart Lock Pro + Connect Wi-Fi password disclosure via hardcoded key (CVE-2019-17098)

Provisional. Candidate score (CFSE Consequence Paths 1.0-candidate); pending independent review. Treat as a structured second opinion, not a final rating.
Paths HIGH Dominant consequence DATA_PRIVACY perception · Evidence EV:3 (reproduced / report-backed) · Liveness HISTORICAL
CPATH IDCPATH-2026-0034
CVE(s)CVE-2019-17098
Device / classAugust Smart Lock Pro + Connect Wi-Fi password disclosure via hardcoded key (CVE-2019-17098) (GENERAL IOT)
VendorAugust
Dominant consequenceDATA_PRIVACY (perception)
Paths verdictHIGH (worst of 1 path)
Published baseline
v3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N · NVD
v3.1 3.5 LOW CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N · Bitdefender via NVD
Baseline relationship▼ Paths higher
Consequence dimension(s)#1 #7 (what these mean)
Scored2026-06-03 · CFSE Consequence Paths v1.0-candidate · validation: provisional
Baseline confidencehigh

Consequence Paths

Paths Assessment

perception

DATA_PRIVACY

HIGH
Reachability RE:2
Complexity EC:3
Consequence DATA_PRIVACY
Scale SR:4 / SX:2
Verdict HIGH
Reachability 2
Complexity 3
Exposure 2
Physical / safety 0
Data / perception 3
Authority 2
Chainability 3
Reuse scale 4
Execution scale 2
Recovery 3
Evidence EV:3 · reproduced / report-backed
Liveness HISTORICAL
Vector CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:2/EC:3/EX:2/PH:0/DP:3/AT:2/CH:3/SR:4/SX:2/OR:3/EV:3/LS:HISTORICAL

Assessment

CFSE Consequence Paths assesses August Smart Lock Pro + Connect Wi-Fi password disclosure via hardcoded key (CVE-2019-17098) at HIGH — the worst of 1 risk path (perception). The dominant consequence is exposure of sensitive data.

Vulnerability

August Smart Lock Pro + Connect Wi-Fi password disclosure via hardcoded key (CVE-2019-17098). Reported attack vector: Adjacent network (AV:A); attacker within Wi-Fi range during/around device provisioning.

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

DATA_PRIVACYHIGH

CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:2/EC:3/EX:2/PH:0/DP:3/AT:2/CH:3/SR:4/SX:2/OR:3/EV:3/LS:HISTORICAL

Exposure EX=2 (reachability-bound) · bands PH=MONITOR · DP=HIGH · AT=ELEVATED → base HIGH · caps privacy-only cap → assessed HIGH.

Published baseline

The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.

Sources

Score it yourself in the calculator Review this score
Cite this entry: CFSE Consequence Paths Registry v1.0-candidate, entry CPATH-2026-0034 (“August Smart Lock Pro + Connect Wi-Fi password disclosure via hardcoded key (CVE-2019-17098)”), paths.cfse.ai/CPATH-2026-0034 (published 2026-06-03).