logo

Two Santa Cruz students uncover security bug that could let millions do their laundry for free

ID: 64246f76-e235-53c5-85f8-3d3d98f78f4b

STIX ID: report--64246f76-e235-53c5-85f8-3d3d98f78f4b

Feed Name: TechCrunch Security News

Threat Score
65/100

Date Published: 2024-05-17

Date Updated: 2026-04-23

Author: Zack Whittaker

...
...

Two UC Santa Cruz students discovered and responsibly disclosed an API security vulnerability in CSC ServiceWorks' CSC Go mobile app that allowed client-side manipulation of account balances and direct commands to over a million connected laundry machines; they demonstrated creating arbitrarily large balances, starting cycles without payment, and remote enumeration/interaction of devices. The students reported the issue to CSC and CERT but received little initial response; CSC later acknowledged the flaw, worked with suppliers to remediate, and pledged to improve security reporting, while the researchers warned of financial loss and potential safety risks from internet-connected appliances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.