A Bluetooth flaw in one of Europe’s most widely used smart door locks let anyone within range of the front door send an unlock command straight to the hardware, with no app, PIN, or keypad touch required. Security researchers at NCC Group catalogued the bug as one of eleven separate issues found across the lock lineup made by Austrian smart-lock maker Nuki, and rated it 8.0 out of 10 for severity.
The Flaw Lived Inside the Lock’s Bluetooth Handshake
The most serious of the batch, tracked as CVE-2022-32507 in the National Vulnerability Database, came down to a missing permission check. The lock’s Bluetooth Low Energy API accepted commands from devices that had never proven who they were, according to a technical breakdown from Hackread, which reported that “insufficient access controls in the Bluetooth Low Energy (BLE) Nuki API allowed unprivileged users to send high privileged commands” straight to the lock’s motor, known as the Keyturner. An attacker didn’t need the homeowner’s phone, the app, or a stolen code. Standing near enough for a Bluetooth signal to reach the door was enough to fire off a legitimate unlock instruction.
A companion bug, CVE-2022-32505, worked differently but hit the same wireless channel. The National Vulnerability Database’s own entry describes it plainly: it was “possible to send multiple BLE malformed packets to block some of the functionality and reboot the device,” again with no login of any kind.
Key points from the disclosure:
- NCC Group identified 11 vulnerabilities total, spanning the Nuki Smart Lock, Nuki Bridge, Nuki Opener, Nuki Keypad, and the companion smartphone app.
- CVE-2022-32507, the Bluetooth access-control flaw, scored 8.0 on the CVSS severity scale and required no authentication whatsoever.
- A separate flaw, CVE-2022-32509, scored 8.8 and involved the lock’s app failing to validate certificates on its network traffic, opening the door to intercepted or altered data.
- Researchers also found exposed debug interfaces that could be abused by someone with physical access to a lock’s circuit board, according to reporting from Latest Hacking News.

What makes the Bluetooth-based bug notable is how little it asked of an attacker. Most smart-lock exploits documented over the years have required cloning a key fob, intercepting an app session, or physically tampering with the device. This one worked because the lock trusted commands it should have questioned, over a radio protocol designed to work within about 30 feet.
Nuki Patched Before the Findings Went Public
NCC Group notified Nuki privately in April 2022, and the company began pushing firmware and app updates within weeks, according to both Hackread and Latest Hacking News. The researchers held their full technical write-up back until those fixes were already live, standard practice for responsible disclosure. Nuki’s own security update page still lists the patched firmware versions tied to that round of fixes as the current baseline for every affected product line, including the Smart Lock 2.0, Smart Lock 3.0, and both generations of the Nuki Bridge.
The episode is now a few years old, but it’s a useful reminder for anyone shopping for a Bluetooth deadbolt today: the wireless handshake between your phone and your front door is itself a piece of software, and it can have bugs like any other. Checking that a lock’s firmware auto-updates, and that it actually has, is as much a part of home security now as checking the deadbolt itself.

Leave a Reply