logo

Notes on ThroughTek Kalay Vulnerabilities and Their Impact on the IoT Ecosystem

ID: 0d17dd82-8264-5f5a-b8a0-f8ddb25a30af

STIX ID: report--0d17dd82-8264-5f5a-b8a0-f8ddb25a30af

Feed Name: Bitdefender Labs

Threat Score
75/100

Date Published: 2024-05-15

Date Updated: 2026-04-27

Author: Bitdefender

...
...

**Executive summary:** Bitdefender discloses four vulnerabilities (CVE-2023-6321 through CVE-2023-6324) in the ThroughTek Kalay IoT platform that—when chained—allow attackers to obtain root access and, following local network probing, execute code remotely on affected devices (notably Owlet Cam v1/v2, Wyze Cam v3, and Roku Indoor Camera SE); the report includes technical analyses, coordinated disclosure timelines, and links to vendor-specific whitepapers and CVE entries, and notes that patches have been issued.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.