Nexx Smart Garage Doors Vulnerable to Remote Hacking

Multiple vulnerabilities have been discovered in Nexx smart devices that can be exploited to control garage doors, disable home alarms, or smart plugs. The most significant discovery is the use of universal credentials that are hardcoded in the firmware and also easy to obtain from the client communication with Nexx's API. The vendor has yet to acknowledge and fix the five security issues disclosed publicly, with severity scores ranging from medium to critical. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published a relevant alert, warning owners of Nexx products that attackers could access sensitive information, execute API requests, or hijack their devices.
- Hackers can open Nexx garage doors remotely, and there's no fix BleepingComputer
- Open garage doors anywhere in the world by exploiting this “smart” device Ars Technica
- US government warning! What if anyone could open your garage door? Naked Security
- Research: Nexx Smart Home Devices Could Get Hacked Gizmodo
- Heads up: Nexx smart garage doors can be hacked and operated remotely Android Police
Reading Insights
0
0
2 min
vs 3 min read
82%
589 → 104 words
Want the full story? Read the original article
Read on BleepingComputer