Hole in Mobile Apps Leave Home Automation Systems Vulnerable to Hacking
ID: e21c2600-38e0-5db3-8e62-14c836780ee7
STIX ID: report--e21c2600-38e0-5db3-8e62-14c836780ee7
Feed Name: Security Ledger
A Rapid7 researcher found that the Android apps for Wink Hub 2 and Insteon Hub store authentication credentials and OAuth tokens in plaintext (persisting until manual logout and sometimes not revoked), and that Insteon’s wireless protocol transmits unencrypted commands vulnerable to capture-and-replay attacks; the researcher demonstrated replaying a garage-door open/close signal with an SDR. Vendors have released or planned fixes for app storage issues, but the threats remain exploitable via compromised phones or physical proximity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
