Smart Doorbell Security Risks & IoT Vulnerabilities
ID: 386a7222-3b0a-561e-a09e-94770a7882d8
STIX ID: report--386a7222-3b0a-561e-a09e-94770a7882d8
Feed Name: NCC Research
This NCC Group/Which? assessment details widespread security and privacy weaknesses in multiple smart/connected doorbell models and clones: exposed HTTP control panels with hardcoded credentials, unauthenticated backend APIs that allow configuration and image access, cleartext Wi‑Fi credentials and QR codes, unprotected firmware downloads enabling reverse engineering or malicious updates, and mobile apps leaking sensitive information to third‑party servers. The findings highlight practical risks including device takeover, local network compromise, theft/forensic data recovery, and large-scale privacy mapping, and note discovery of internet‑reachable devices via Shodan.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
