logo

Notes on ThroughTek Kalay Vulnerabilities and Their Impact on the IoT Ecosystem

ID: fb73f780-d1f6-5c30-a8d5-1005e3e07478

STIX ID: report--fb73f780-d1f6-5c30-a8d5-1005e3e07478

Feed Name: Bitdefender Labs

Threat Score
80/100

Date Published: 2024-05-15

Date Updated: 2026-04-27

Author: Bitdefender

...
...

Bitdefender IoT researchers disclosed four high-severity vulnerabilities in the ThroughTek Kalay platform (CVE-2023-6321–6324) that, when chained, allow local attackers to obtain AuthKey/DTLS PSK material, escalate to root, and execute commands on affected IoT cameras. The findings impact multiple vendors (Owlet, Wyze, Roku and others using the Kalay SDK), a coordinated disclosure and firmware/SDK patches were arranged and released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.