logo

Investigating the Wink Hub 2

ID: f9ac479a-6718-5b04-926c-711e6bdc5fce

STIX ID: report--f9ac479a-6718-5b04-926c-711e6bdc5fce

Feed Name: SensePost Blog

Threat Score
30/100

Date Published: 2023-05-26

Date Updated: 2026-04-30

...
...

SensePost researchers performed a hardware teardown and security analysis of the Wink Hub 2, documenting board-level access, UART boot logs, enabled Secure/High Assurance Boot, and exposed services (HTTP, MQTT). They attempted multiple bypass methods — NAND glitching, JTAG, electromagnetic fault injection, USB boot attempts, and TLS interception — observing protections such as HAB, image signature verification, and pinned public keys that prevented remote or persistent compromise; unauthenticated local MQTT and various unverified attack surfaces are noted as potential risks and future research targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.