IoT Cloud Cracked by 'Open Sesame' Over-the-Air Attack
ID: 5da09e74-6817-5a3e-85af-a037750a0aef
STIX ID: report--5da09e74-6817-5a3e-85af-a037750a0aef
Feed Name: Dark Reading
Date Published: 2024-12-12
Date Updated: 2026-04-21
Author: Becky Bracken, Senior Editor, Dark Reading
Claroty Team82 disclosed ten critical vulnerabilities in Ruijie Networks' Reyee cloud platform, including multiple CVEs with CVSS scores of 9.0 and higher, that permit weak-authentication abuse, cloud impersonation, and remote code execution on cloud-connected access points. Researchers demonstrated the "Open Sesame" scenario—using a device serial number obtained from Wi‑Fi beacons plus MQTT weaknesses—to deliver a malicious OS command and obtain a reverse shell; Claroty estimates tens of thousands of potentially affected devices worldwide, and Ruijie has released patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
