logo

IoT Cloud Cracked by 'Open Sesame' Over-the-Air Attack

ID: 5da09e74-6817-5a3e-85af-a037750a0aef

STIX ID: report--5da09e74-6817-5a3e-85af-a037750a0aef

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-12-12

Date Updated: 2026-04-21

Author: Becky Bracken, Senior Editor, Dark Reading

...
...

Claroty Team82 disclosed ten critical vulnerabilities in Ruijie Networks' Reyee cloud platform, including multiple CVEs with CVSS scores of 9.0 and higher, that permit weak-authentication abuse, cloud impersonation, and remote code execution on cloud-connected access points. Researchers demonstrated the "Open Sesame" scenario—using a device serial number obtained from Wi‑Fi beacons plus MQTT weaknesses—to deliver a malicious OS command and obtain a reverse shell; Claroty estimates tens of thousands of potentially affected devices worldwide, and Ruijie has released patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.