+1 (970) 414-2609
  • Active Campaign
  • Global News
Tuesday, June 6, 2023
  • Home
  • About Us
  • Our Experts
  • AI Tools
  • Our Work
    • Education
    • Community
    • Humanitarian
No Result
View All Result
Boys & Girls Clubs of Senegal
No Result
View All Result
Home Cybersecurity

Researchers find severe vulnerabilities in garage door openers and other

by newstalk
April 7, 2023
in Cybersecurity
Reading Time: 2 mins read
A A
464
SHARES
1.8k
VIEWS
Share on FacebookShare on Twitter

TechSpot is about to celebrate its 25th anniversary. TechSpot means tech analysis and advice you can trust.

PSA: A security researcher and US authorities discovered multiple severe vulnerabilities rendering Nexx smart security systems virtually toothless. Those using their devices should find another solution ASAP since Nexx has been radio-silent for two years.

Researcher Sam Sabetan, cooperating with the US Department of Homeland Security (DHS) and the Cybersecurity and Infrastructure Security Agency (CISA), recently published several severe security risks involving Nexx smart home systems. The vulnerabilities allow attackers to quickly seize complete control over garage door openers, smart plugs, and alarm systems from anywhere on Earth.

Nexx offers devices that let users open garage doors, toggle home security systems, and switch smart power outlets on or off through a smartphone app. Earlier this year, Sabetan discovered that the devices’ connections to the company’s cloud use extremely weak security.

When a user registers the Nexx app with the company’s cloud, its servers send a password to the app and device, establishing the connection. Unfortunately, the password is identical for all users. Furthermore, it’s freely available in Nexx’s API and publicly available in each device’s firmware.

Equipped with the password, an attacker with access to Nexx’s servers can remotely open any garage door and switch off devices connected to smart plugs. They can also see users’ email addresses, device IDs, first names, and last initials, allowing hackers to target specific people.

ADVERTISEMENT

While the home alarm doesn’t suffer from this specific vulnerability, it has two equally serious problems. Any registered Nexx user with an alarm’s MAC address can take over that alarm, and the MAC address isn’t tricky to discover. Nexx’s server doesn’t verify bearer tokens, potentially letting bad actors send signals to users’ alarms. All Nexx alarm MAC addresses begin with the same digits – 7C 9E BD F4 – making the remainder of the address easy to brute-force. Additionally, a hacker with the MAC address can hijack a registered alarm by reregistering it under a rogue account, removing access from the original user, and giving the attacker complete control over the security system.

Sabetan, the DHS, and CISA have tried contacting Nexx on multiple occasions since January with no success. The company’s mobile apps are still functional. Its social media accounts and website are still online but have logged no activity since 2021. More concerning is that Nexx’s official Twitter posted a tweet in April 2021 appearing to advertise a Web3 studio, suggesting someone else gained control of the account.

Despite signs indicating Nexx has dropped off the face of the Earth, the company’s online store still operates, and the garage door opener remains available on Amazon. Even if few new customers buy Nexx’s products, Sabetan estimates their vulnerabilities endanger 40,000 devices and 20,000 active accounts. It suggests users immediately stop using the devices and try to contact Nexx for refunds. The CISA recommends disconnecting the devices from the internet, isolating them from business networks, or accessing them through VPN.

If Nexx is defunct, it represents another case of what happens to IoT devices when manufacturers and software developers abandon their products.

news image

Previous Post

Once More, With Feeling: Exploring Relatable Robotics at Disney

Next Post

The Importance of Cybersecurity in the Hospitality Industry: Ensuring Safe

Related Posts

Today’s Cyber Threats Require Modern Cloud Network Security

by editorial@africanews.com redaction africanews
June 3, 2023

Tweet Post Share Annotate Save Print By Narayan Annamalai When cybersecurity measures fail, the results can be devastating and costly....

Read more

United Airlines CISO Deneen DeFiore on elevating cyber’s value to the business

by vladimir karaj
May 28, 2023

Interview May 25, 20238 mins Business IT AlignmentCSO and CISOData and Information Security The airlines’ cyber chief believes storytelling, facilitation,...

Read more

Cyber threats to nuclear weapons

by james bamford
May 26, 2023

“The more connected we get, the more we need to be concerned about security. The more we depend on technology,...

Read more

Navigating the Cyber Landscape: How to Protect Your Data from Threats

by BGC Senegal
May 21, 2023

As the digital world rapidly grows, navigating the cyber landscape can be daunting. With so many potential threats to data,...

Read more

Cyber beware: Unmasking the Perils of the Digital Domain

by BGC Senegal
May 21, 2023

Technology has revolutionised the way we communicate, shop, and work. But with it's rapid advancements come hidden dangers lurking in...

Read more

The Growing Web of Cyber Threats

by BGC Senegal
May 21, 2023

As the Internet of Things expands, connecting billions of devices across the globe, the web of cyber threats grows infinitely...

Read more
Next Post

The Importance of Cybersecurity in the Hospitality Industry: Ensuring Safe

ADVERTISEMENT

Trending Posts

Brain Teasers

Deep-Sea Creatures That Will Haunt Your Nightmares

by BGC Senegal
June 6, 2023

Read more

Deep-Sea Creatures That Will Haunt Your Nightmares

If You Spot a Rubber Band on Your Door, Remove It ASAP

How Does This Illusion Work?

We Expanded Iconic Video Game Covers Using AI

95 Brainteasers for the True Riddle Maestro

Why Even AI Can’t Bring the Dinosaurs Back

Load More

Popular Posts

Learning English: A Non-English Speaker’s Journey

by BGC Senegal
May 21, 2023

When I first decided to study English, I was filled with hope and excitement. Little did I know the hard...

What is computer programming?

by BGC Senegal
January 29, 2023

What is Computer Programming? Computer programming is an essential part of today's digital world. It is a process of writing,...

Upgrade Your Word Power with Suffixes!

by BGC Senegal
May 21, 2023

Are you looking for a way to improve your English vocabulary? Try adding suffixes onto the ends of words to...

Facebook Twitter LinkedIn Youtube

NEWSLETTER

Subscribe to our newsletter and be the first to know about our upcoming events and programs.

QUICK LINKS

  • About Us
  • Learning Center
  • Active Campaign
  • Privacy Policy
  • Terms and Conditions
  • Contact us
  • Global News

CONTACT INFO

  • info@senegalbgc.org
  • For donations contact us at: donate@senegalbgc.org

© 2019-2023 Boys & Girls Clubs of Senegal. We are a 501 (C)(3) organization and donations are tax deductible. - EIN: 83-3699796

No Result
View All Result
  • Home
  • About Us
  • Our Experts
  • AI Tools
  • Our Work
    • Education
    • Community
    • Humanitarian

© 2019-2023 Boys & Girls Clubs of Senegal. We are a 501 (C)(3) organization and donations are tax deductible. - EIN: 83-3699796

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
Cookie SettingsAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT