Site navigation

Researchers Find Security Vulnerabilities in Popular Smart Bulb

Michael Edgar

,

Smart Home attack IoT devices
A top-selling TP-Link smart bulb sold on popular marketplaces has been found to be vulnerable to a number of attack possibilities, which could even uncover Wi-Fi passwords. 

Researchers from the University of London along with Universita di Catania in Italy discovered four significant vulnerabilities in the popular TP-Link smart bulb and the Tapo app. This, according to researchers, underscores the broader security concerns around smart IoT devices. 

The vulnerabilities identified with the TP-Link Tapo L530E smart bulb range from medium to high severity in their vulnerability score. The most dangerous allows attackers to impersonate the device during the session key exchange, giving the attacker a chance to steal user passwords and manipulate the devices. 

Another potentially dangerous flaw comes from a hard-coded short checksum shared secret, meaning the “secret” used for authentication or encryption doesn’t change. Attackers can obtain it through brute forcing or by decompiling the app.

Among all possible attack scenarios, the most worrying is a combination use of the two. This allows the attacker to impersonate the bulb to retrieve the account details, then extract the user’s Wi-Fi SSID, and compromise all other devices connected to the network.

The vulnerabilities were first reported by Bleeping computer, who have since reached out to TP-Link. The company acknowledged all the findings and said they would implement fixes to the app and bulb’s firmware “in due course”. 

During their assessment of the TP-Link bulb, the researchers found that “Exploiting the vulnerabilities was moderately challenging but devising appropriate fixes was harder.”

This study comes on the backdrop of IoT devices in the UK expected to grow to over 150 million next year, up from just 13 million in 2006 according to the UK Government. The same report also notes that the most growth will be in the automotive markets, and consumer electronics and utilities sectors. 


Recommended


Another report by Eco Experts also found that almost a quarter (23%) of 66.4 million Brits own at least one smart item, and over half (57%) of homes in the UK contain a smart device.

In relation, another report by Banklesstimes found that four in ten smart home devices may be vulnerable to cyber-attacks, and 68% of these are due to weak credentials, allowing the attackers to glean passwords like the researchers discovered in the TP-Link bulb. 

In response to the discovery, the experts suggest isolating IoT devices from your network to limit potential exposure, update firmware and apps regularly, and use multi-factor authentication on accounts associated with the IoT devices for an extra layer of security. 

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data