Firm Finds Crypto Keys Recycled on Thousands of Devices
ID: 953e308f-60c4-58bf-955a-c7dbb0d3fef3
STIX ID: report--953e308f-60c4-58bf-955a-c7dbb0d3fef3
Feed Name: Security Ledger
SEC Consult analyzed firmware from more than 4,000 embedded devices across ~70 vendors and discovered over 580 unique private encryption keys reused across devices—affecting hundreds of thousands of systems (including one Broadcom SDK certificate used by ~480,000 devices and a Texas Instruments SDK-linked certificate in ~300,000 devices). These baked‑in keys, many actively used for HTTPS and SSH, create a large attack surface enabling eavesdropping, impersonation, and remote compromise of routers, IP cameras, NAS, VoIP phones and other embedded hardware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
