logo

My Adventures Hacking the iParcelBox

ID: cc5132be-cad0-51a6-90d9-4edc6ac4bea3

STIX ID: report--cc5132be-cad0-51a6-90d9-4edc6ac4bea3

Feed Name: McAfee Labs Blog

Threat Score
70/100

Date Published: 2020-06-18

Date Updated: 2026-04-28

Author: Sam Quinn

...
...

McAfee ATR researched the iParcelBox smart parcel box and discovered multiple critical security issues: exposed admin credentials and GitHub token in logs, inappropriate use of shared AWS certificates/keys and Cognito/DynamoDB access that allowed database enumeration by DeviceID (MAC), and RPC-over-MQTT functionality that enabled remote administrative control (including unlocking boxes and retrieving Wi‑Fi credentials). The team demonstrated local and remote attack paths, reported the problems to iParcelBox, and the vendor deployed fixes within 12 hours (rotated admin credentials, constrained certificate/key scope, added API checks and improved SSL handling).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.