Students Spot Washing Machine App Flaw That Gives Out Free Cycles
ID: 21a7f45b-f335-5fd3-b797-6e09a3229390
STIX ID: report--21a7f45b-f335-5fd3-b797-6e09a3229390
Feed Name: Dark Reading
Date Published: 2024-05-20
Date Updated: 2026-04-21
Author: Kristina Beek, Associate Editor, Dark Reading
Researchers at UCSC discovered and publicly disclosed an API security flaw in CSC ServiceWorks' CSC Go mobile app that allows remote commands to laundry machines (including initiating cycles without funds) and arbitrary account-balance manipulation; they demonstrated free cycles and the ability to add multimillion-dollar balances, reported the issue to the vendor without meaningful response, and say the vulnerability remains unpatched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
