home.social

#iotsec — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #iotsec, aggregated by home.social.

fetched live
  1. CVE-2026-13214 (CRITICAL, CVSS 9.8) in Zephyr OCPP 1.6 client: Unbounded strcpy() in parse_getconfig_msg() enables RCE/DoS via stack overflow. Affects =4.3.0, >=4.3.0 <4.4.2. Restrict untrusted WebSocket access. Patch status pending. radar.offseq.com/threat/cve-20 #OffSeq #Zephyr #CVE202613214 #IoTSec

  2. CVE-2026-13214 (CRITICAL, CVSS 9.8) in Zephyr OCPP 1.6 client: Unbounded strcpy() in parse_getconfig_msg() enables RCE/DoS via stack overflow. Affects =4.3.0, >=4.3.0 <4.4.2. Restrict untrusted WebSocket access. Patch status pending. radar.offseq.com/threat/cve-20 #OffSeq #Zephyr #CVE202613214 #IoTSec

  3. CVE-2026-13214 (CRITICAL, CVSS 9.8) in Zephyr OCPP 1.6 client: Unbounded strcpy() in parse_getconfig_msg() enables RCE/DoS via stack overflow. Affects =4.3.0, >=4.3.0 <4.4.2. Restrict untrusted WebSocket access. Patch status pending. radar.offseq.com/threat/cve-20 #OffSeq #Zephyr #CVE202613214 #IoTSec

  4. CVE-2026-13214 (CRITICAL, CVSS 9.8) in Zephyr OCPP 1.6 client: Unbounded strcpy() in parse_getconfig_msg() enables RCE/DoS via stack overflow. Affects =4.3.0, >=4.3.0 <4.4.2. Restrict untrusted WebSocket access. Patch status pending. radar.offseq.com/threat/cve-20 #OffSeq #Zephyr #CVE202613214 #IoTSec

  5. CVE-2026-76590: CRITICAL stack buffer overflow in TRENDnet TEW-755AP (/cgi-bin/wan.cgi, CVSS 9.4). Remote code execution possible. No patch — restrict access, monitor endpoints. Exploit code public, no active attacks yet. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSec #CVE2026

  6. CVE-2026-76590: CRITICAL stack buffer overflow in TRENDnet TEW-755AP (/cgi-bin/wan.cgi, CVSS 9.4). Remote code execution possible. No patch — restrict access, monitor endpoints. Exploit code public, no active attacks yet. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSec #CVE2026

  7. CVE-2026-76590: CRITICAL stack buffer overflow in TRENDnet TEW-755AP (/cgi-bin/wan.cgi, CVSS 9.4). Remote code execution possible. No patch — restrict access, monitor endpoints. Exploit code public, no active attacks yet. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSec #CVE2026

  8. CVE-2026-76590: CRITICAL stack buffer overflow in TRENDnet TEW-755AP (/cgi-bin/wan.cgi, CVSS 9.4). Remote code execution possible. No patch — restrict access, monitor endpoints. Exploit code public, no active attacks yet. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSec #CVE2026

  9. 🔎 HIGH-severity (CVSS 8.7) buffer overflow in Shenzhen Libituo LBT-T300-HW1 (v1.2.0 – 1.2.8), CVE-2026-7674. Web Management Interface at risk, remote exploit possible. No patch yet — restrict access & stay alert. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSec #Infosec

  10. 🔎 HIGH-severity (CVSS 8.7) buffer overflow in Shenzhen Libituo LBT-T300-HW1 (v1.2.0 – 1.2.8), CVE-2026-7674. Web Management Interface at risk, remote exploit possible. No patch yet — restrict access & stay alert. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSec #Infosec

  11. 🔎 HIGH-severity (CVSS 8.7) buffer overflow in Shenzhen Libituo LBT-T300-HW1 (v1.2.0 – 1.2.8), CVE-2026-7674. Web Management Interface at risk, remote exploit possible. No patch yet — restrict access & stay alert. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSec #Infosec

  12. 🔎 HIGH-severity (CVSS 8.7) buffer overflow in Shenzhen Libituo LBT-T300-HW1 (v1.2.0 – 1.2.8), CVE-2026-7674. Web Management Interface at risk, remote exploit possible. No patch yet — restrict access & stay alert. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSec #Infosec

  13. 🚨 CRITICAL: Totolink A8000RU (7.1cu.643_b20200521) suffers from OS command injection (CVE-2026-7203). Remote, unauthenticated attackers can fully compromise affected routers. No patch confirmed — disable remote mgmt & isolate. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSec

  14. 🚨 CRITICAL: Totolink A8000RU (7.1cu.643_b20200521) suffers from OS command injection (CVE-2026-7203). Remote, unauthenticated attackers can fully compromise affected routers. No patch confirmed — disable remote mgmt & isolate. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSec

  15. 🚨 CRITICAL: Totolink A8000RU (7.1cu.643_b20200521) suffers from OS command injection (CVE-2026-7203). Remote, unauthenticated attackers can fully compromise affected routers. No patch confirmed — disable remote mgmt & isolate. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSec

  16. 🚨 CRITICAL: Totolink A8000RU (7.1cu.643_b20200521) suffers from OS command injection (CVE-2026-7203). Remote, unauthenticated attackers can fully compromise affected routers. No patch confirmed — disable remote mgmt & isolate. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSec

  17. 🔒 CVE-2026-5851: CRITICAL OS command injection in Totolink A7100RU (7.4cu.2313_b20191024). Remote, unauthenticated RCE possible via /cgi-bin/cstecgi.cgi. Exploit public, no patch. Isolate device and check for updates! radar.offseq.com/threat/cve-20 #OffSeq #CVE20265851 #IoTSec

  18. 🔒 CVE-2026-5851: CRITICAL OS command injection in Totolink A7100RU (7.4cu.2313_b20191024). Remote, unauthenticated RCE possible via /cgi-bin/cstecgi.cgi. Exploit public, no patch. Isolate device and check for updates! radar.offseq.com/threat/cve-20 #OffSeq #CVE20265851 #IoTSec

  19. 🔒 CVE-2026-5851: CRITICAL OS command injection in Totolink A7100RU (7.4cu.2313_b20191024). Remote, unauthenticated RCE possible via /cgi-bin/cstecgi.cgi. Exploit public, no patch. Isolate device and check for updates! radar.offseq.com/threat/cve-20 #OffSeq #CVE20265851 #IoTSec

  20. 🔒 CVE-2026-5851: CRITICAL OS command injection in Totolink A7100RU (7.4cu.2313_b20191024). Remote, unauthenticated RCE possible via /cgi-bin/cstecgi.cgi. Exploit public, no patch. Isolate device and check for updates! radar.offseq.com/threat/cve-20 #OffSeq #CVE20265851 #IoTSec

  21. Masjesu Botnet neu unterwegs: DDoS-for-Hire via Telegram, infiziert IoT (Router/Gateways, multi-arch). Hohe Persistence, vermeidet Blacklists/CI. Default-Passwörter killen! THN: thehackernews.com/2026/04/masj #IoTSec #DDoS

  22. 🚨 CRITICAL: CVE-2026-2686 in SECCN Dingcheng G10 (v3.1.0.181203) enables unauthenticated remote OS command injection via the 'User' param in /cgi-bin/session_login.cgi. Exploit code is public. Restrict access & monitor! radar.offseq.com/threat/cve-20 #OffSeq #CVE20262686 #IoTSec

  23. 🚨 CRITICAL: CVE-2026-2686 in SECCN Dingcheng G10 (v3.1.0.181203) enables unauthenticated remote OS command injection via the 'User' param in /cgi-bin/session_login.cgi. Exploit code is public. Restrict access & monitor! radar.offseq.com/threat/cve-20 #OffSeq #CVE20262686 #IoTSec

  24. 🚨 CRITICAL: CVE-2026-2686 in SECCN Dingcheng G10 (v3.1.0.181203) enables unauthenticated remote OS command injection via the 'User' param in /cgi-bin/session_login.cgi. Exploit code is public. Restrict access & monitor! radar.offseq.com/threat/cve-20 #OffSeq #CVE20262686 #IoTSec

  25. 🚨 CRITICAL: CVE-2026-2686 in SECCN Dingcheng G10 (v3.1.0.181203) enables unauthenticated remote OS command injection via the 'User' param in /cgi-bin/session_login.cgi. Exploit code is public. Restrict access & monitor! radar.offseq.com/threat/cve-20 #OffSeq #CVE20262686 #IoTSec

  26. ⚠️ CVE-2025-41108 (CRITICAL): Ghost Robotics Vision 60 v0.27.2 lets attackers hijack robots by spoofing control commands over MAVLink (no auth/encryption). Segment networks & monitor traffic while awaiting patch. radar.offseq.com/threat/cve-20 #OffSeq #CVE202541108 #Robotics #IoTSec

  27. ⚠️ CVE-2025-41108 (CRITICAL): Ghost Robotics Vision 60 v0.27.2 lets attackers hijack robots by spoofing control commands over MAVLink (no auth/encryption). Segment networks & monitor traffic while awaiting patch. radar.offseq.com/threat/cve-20 #OffSeq #CVE202541108 #Robotics #IoTSec

  28. ⚠️ CVE-2025-41108 (CRITICAL): Ghost Robotics Vision 60 v0.27.2 lets attackers hijack robots by spoofing control commands over MAVLink (no auth/encryption). Segment networks & monitor traffic while awaiting patch. radar.offseq.com/threat/cve-20 #OffSeq #CVE202541108 #Robotics #IoTSec

  29. ⚠️ CVE-2025-41108 (CRITICAL): Ghost Robotics Vision 60 v0.27.2 lets attackers hijack robots by spoofing control commands over MAVLink (no auth/encryption). Segment networks & monitor traffic while awaiting patch. radar.offseq.com/threat/cve-20 #OffSeq #CVE202541108 #Robotics #IoTSec

  30. ⚠️ CVE-2025-41108 (CRITICAL): Ghost Robotics Vision 60 v0.27.2 lets attackers hijack robots by spoofing control commands over MAVLink (no auth/encryption). Segment networks & monitor traffic while awaiting patch. radar.offseq.com/threat/cve-20 #OffSeq #CVE202541108 #Robotics #IoTSec

  31. In the #iotsec front, here's a new package to play with, involving #mud (manufacturer usage descriptions) and RFC 8520. mudcerts (github.com/iot-onboarding/mudc) is a Go package that can generate a demo CA, signer cert, and #IEEE 802.1AR cert, as well as verify it.

  32. In the #iotsec front, here's a new package to play with, involving #mud (manufacturer usage descriptions) and RFC 8520. mudcerts (github.com/iot-onboarding/mudc) is a Go package that can generate a demo CA, signer cert, and #IEEE 802.1AR cert, as well as verify it.

  33. In the #iotsec front, here's a new package to play with, involving #mud (manufacturer usage descriptions) and RFC 8520. mudcerts (github.com/iot-onboarding/mudc) is a Go package that can generate a demo CA, signer cert, and #IEEE 802.1AR cert, as well as verify it.

  34. In the #iotsec front, here's a new package to play with, involving #mud (manufacturer usage descriptions) and RFC 8520. mudcerts (github.com/iot-onboarding/mudc) is a Go package that can generate a demo CA, signer cert, and #IEEE 802.1AR cert, as well as verify it.

  35. In the #iotsec front, here's a new package to play with, involving #mud (manufacturer usage descriptions) and RFC 8520. mudcerts (github.com/iot-onboarding/mudc) is a Go package that can generate a demo CA, signer cert, and #IEEE 802.1AR cert, as well as verify it.

  36. Hypponen's Law ( @mikko ) confirmed (again):

    "At the Usenix Workshop on Offensive Technologies earlier this week, researchers from UC San Diego and Northeastern University revealed a technique that would allow anyone with a few hundred dollars of hardware to hack Shimano wireless gear-shifting systems of the kind used by many of the top cycling teams in the world, including in recent events like the Olympics and the Tour de France. Their relatively simple radio attack would allow cheaters or vandals to spoof signals from as far as 30 feet away that trigger a target bike to unexpectedly shift gears or to jam its shifters and lock the bike into the wrong gear."

    Citation:
    wired.com/story/shimano-wirele

    #iot #infosec #cybersecurity #IoTSec

  37. Hypponen's Law ( @mikko ) confirmed (again):

    "At the Usenix Workshop on Offensive Technologies earlier this week, researchers from UC San Diego and Northeastern University revealed a technique that would allow anyone with a few hundred dollars of hardware to hack Shimano wireless gear-shifting systems of the kind used by many of the top cycling teams in the world, including in recent events like the Olympics and the Tour de France. Their relatively simple radio attack would allow cheaters or vandals to spoof signals from as far as 30 feet away that trigger a target bike to unexpectedly shift gears or to jam its shifters and lock the bike into the wrong gear."

    Citation:
    wired.com/story/shimano-wirele

    #iot #infosec #cybersecurity #IoTSec

  38. Hypponen's Law ( @mikko ) confirmed (again):

    "At the Usenix Workshop on Offensive Technologies earlier this week, researchers from UC San Diego and Northeastern University revealed a technique that would allow anyone with a few hundred dollars of hardware to hack Shimano wireless gear-shifting systems of the kind used by many of the top cycling teams in the world, including in recent events like the Olympics and the Tour de France. Their relatively simple radio attack would allow cheaters or vandals to spoof signals from as far as 30 feet away that trigger a target bike to unexpectedly shift gears or to jam its shifters and lock the bike into the wrong gear."

    Citation:
    wired.com/story/shimano-wirele

    #iot #infosec #cybersecurity #IoTSec

  39. Hypponen's Law ( @mikko ) confirmed (again):

    "At the Usenix Workshop on Offensive Technologies earlier this week, researchers from UC San Diego and Northeastern University revealed a technique that would allow anyone with a few hundred dollars of hardware to hack Shimano wireless gear-shifting systems of the kind used by many of the top cycling teams in the world, including in recent events like the Olympics and the Tour de France. Their relatively simple radio attack would allow cheaters or vandals to spoof signals from as far as 30 feet away that trigger a target bike to unexpectedly shift gears or to jam its shifters and lock the bike into the wrong gear."

    Citation:
    wired.com/story/shimano-wirele

    #iot #infosec #cybersecurity #IoTSec

  40. Hypponen's Law ( @mikko ) confirmed (again):

    "At the Usenix Workshop on Offensive Technologies earlier this week, researchers from UC San Diego and Northeastern University revealed a technique that would allow anyone with a few hundred dollars of hardware to hack Shimano wireless gear-shifting systems of the kind used by many of the top cycling teams in the world, including in recent events like the Olympics and the Tour de France. Their relatively simple radio attack would allow cheaters or vandals to spoof signals from as far as 30 feet away that trigger a target bike to unexpectedly shift gears or to jam its shifters and lock the bike into the wrong gear."

    Citation:
    wired.com/story/shimano-wirele

    #iot #infosec #cybersecurity #IoTSec

  41. Dutch ethical hacker Wietse Boonstra discovered a critical vulnerability in solar panel systems that could have allowed disruption of 4 million systems across 150 countries. The vulnerability affected systems made by Enphase, an American company. Boonstra found a flaw that allowed him to become an administrator of multiple accounts without permission.

    Sources:

    1. Dutch Institute for Vulnerability Disclosure (DIVD) report: divd.nl/newsroom/articles/divd

    2. Original reporting from Follow the Money (FTM), a Dutch investigative outlet: archive.is/BVR80

    3. Euractiv summary article (English): euractiv.com/section/energy-en

    #infosec #cybersecurity #renewableenergy #ethicalhacking #iotsec

  42. Dutch ethical hacker Wietse Boonstra discovered a critical vulnerability in solar panel systems that could have allowed disruption of 4 million systems across 150 countries. The vulnerability affected systems made by Enphase, an American company. Boonstra found a flaw that allowed him to become an administrator of multiple accounts without permission.

    Sources:

    1. Dutch Institute for Vulnerability Disclosure (DIVD) report: divd.nl/newsroom/articles/divd

    2. Original reporting from Follow the Money (FTM), a Dutch investigative outlet: archive.is/BVR80

    3. Euractiv summary article (English): euractiv.com/section/energy-en

    #infosec #cybersecurity #renewableenergy #ethicalhacking #iotsec

  43. Dutch ethical hacker Wietse Boonstra discovered a critical vulnerability in solar panel systems that could have allowed disruption of 4 million systems across 150 countries. The vulnerability affected systems made by Enphase, an American company. Boonstra found a flaw that allowed him to become an administrator of multiple accounts without permission.

    Sources:

    1. Dutch Institute for Vulnerability Disclosure (DIVD) report: divd.nl/newsroom/articles/divd

    2. Original reporting from Follow the Money (FTM), a Dutch investigative outlet: archive.is/BVR80

    3. Euractiv summary article (English): euractiv.com/section/energy-en

    #infosec #cybersecurity #renewableenergy #ethicalhacking #iotsec

  44. Dutch ethical hacker Wietse Boonstra discovered a critical vulnerability in solar panel systems that could have allowed disruption of 4 million systems across 150 countries. The vulnerability affected systems made by Enphase, an American company. Boonstra found a flaw that allowed him to become an administrator of multiple accounts without permission.

    Sources:

    1. Dutch Institute for Vulnerability Disclosure (DIVD) report: divd.nl/newsroom/articles/divd

    2. Original reporting from Follow the Money (FTM), a Dutch investigative outlet: archive.is/BVR80

    3. Euractiv summary article (English): euractiv.com/section/energy-en

    #infosec #cybersecurity #renewableenergy #ethicalhacking #iotsec

  45. Dutch ethical hacker Wietse Boonstra discovered a critical vulnerability in solar panel systems that could have allowed disruption of 4 million systems across 150 countries. The vulnerability affected systems made by Enphase, an American company. Boonstra found a flaw that allowed him to become an administrator of multiple accounts without permission.

    Sources:

    1. Dutch Institute for Vulnerability Disclosure (DIVD) report: divd.nl/newsroom/articles/divd

    2. Original reporting from Follow the Money (FTM), a Dutch investigative outlet: archive.is/BVR80

    3. Euractiv summary article (English): euractiv.com/section/energy-en

    #infosec #cybersecurity #renewableenergy #ethicalhacking #iotsec

  46. @ted also, here's some people silently triggering voice commands with lasers

    "Breaking Into a Smart Home With A Laser - Smarter Every Day 229"

    youtube.com/watch?v=ozIKwGt38L

    #SmarterEveryDay #IoT #IoTSec