Shelly Wall Display exposed RPC over Bluetooth
ID: b0821fb7-f016-551a-a138-b8eb7a60936b
STIX ID: report--b0821fb7-f016-551a-a138-b8eb7a60936b
Feed Name: Pen Test Partners Blog
The Shelly Wall Display shipped with an inaccurate internal temperature sensor and a bundled Bluetooth temperature sensor that required Bluetooth to remain enabled; unlike other Shelly devices it did not allow RPC to be disabled independently of Bluetooth. This design meant RPC over Bluetooth remained exposed and could be used by an attacker in range to reconfigure the device, connect it to an attacker-controlled network, and pivot to other devices; Shelly released firmware fixes (stable 2.6.2) to address the issue and users are advised to update or disable Bluetooth if they don't use the external sensor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
