logo

Hole in Mobile Apps Leave Home Automation Systems Vulnerable to Hacking

ID: e21c2600-38e0-5db3-8e62-14c836780ee7

STIX ID: report--e21c2600-38e0-5db3-8e62-14c836780ee7

Feed Name: Security Ledger

Threat Score
55/100

Date Published: 2017-09-27

Date Updated: 2026-04-26

Author: Ionut Ilascu

...
...

A Rapid7 researcher found that the Android apps for Wink Hub 2 and Insteon Hub store authentication credentials and OAuth tokens in plaintext (persisting until manual logout and sometimes not revoked), and that Insteon’s wireless protocol transmits unencrypted commands vulnerable to capture-and-replay attacks; the researcher demonstrated replaying a garage-door open/close signal with an SDR. Vendors have released or planned fixes for app storage issues, but the threats remain exploitable via compromised phones or physical proximity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.