logo

Reverse Engineering a Smart Lock

ID: 97068de1-71f4-5e08-a86c-7f097cb3d241

STIX ID: report--97068de1-71f4-5e08-a86c-7f097cb3d241

Feed Name: Black Hills Infosec Blog

Threat Score
70/100

Date Published: 2020-08-27

Date Updated: 2026-04-27

Author: BHIS

...
...

This technical research analyzes Guardtec KeyWe Smart Lock internals and demonstrates that weak key derivation (a partly predictable CommonKey), combined with reversible App/Door key generation and captured Bluetooth HCI traffic, allows an attacker with suitable access to perform a replay attack to unlock the device; the author reproduces the F‑Secure findings, uses Frida and btsnoop logs to extract keys and eKey material, and provides a proof‑of‑concept replay unlocking the lock while recommending app updates and firmware capability as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.