HT TECH wants to start sending you push notifications. Click allow to subscribe

Smart bulb can allow attackers to hack computer networks in your home: Check Point report

The researchers used the Hue lightbulb as a platform to take over the bulbs’ control bridge and ultimately, attacking the target’s computer network.

By: INDO ASIAN NEWS SERVICE
Updated on: Aug 20 2022, 19:23 IST
The researchers from cybersecurity firm Check Point discovered vulnerabilities in the communication protocol used by Philips Hue smart lightbulbs (Amazon/Philips)

Security researchers on Wednesday warned that cyber criminals could exploit an Internet of Things (IoT) network - smart light bulbs and their control bridge -- to launch attacks on conventional computer networks in homes, businesses or even smart cities.

The researchers from cybersecurity firm Check Point discovered vulnerabilities in the communication protocol used by Philips Hue smart lightbulbs -- a marquee smart home device that relies on the Zigbee protocol.

You may be interested in

Mobiles Tablets Laptops
34% OFF
Philips Xenium E172
  • Black
₹1,381₹2,099
Buy now
34% OFF
Philips Xenium E125
  • Black
₹1,381₹2,099
Buy now
34% OFF
Philips Xenium E168
  • Black
₹1,381₹2,099
Buy now
20% OFF
Philips E102A
  • Black
₹960₹1,200
Buy now
21% OFF
Acer Swift Go SFG14 41 NX KG3SI 002 Laptop
  • Pure Silver
  • 8 GB RAM
  • 512 GB SSD
₹58,990₹74,999
Buy now
39% OFF
Acer Aspire 5 A515 57G Laptop
  • Gray
  • 16 GB RAM
  • 512 GB SSD
₹54,949₹89,999
Buy now
22% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹33,499₹42,999
Buy now
39% OFF
Asus VivoBook 15 X515JA BQ322WS Laptop
  • Transparent Silver
  • 8 GB RAM
  • 512 GB SSD
₹31,490₹51,990
Buy now
34% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹26,299₹39,999
Buy now
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
32% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,790₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹14,999
Check details

The research, which was done with the help of the Check Point Institute for Information Security (CPIIS) in Tel Aviv University, Israel was disclosed to Philips and Signify (owner of the Philips Hue brand) in November 2019.

Also read: Looking for a smartphone? To check mobile finder click here.

Signify confirmed the existence of the vulnerability in their product, and issued a patched firmware version (Firmware 1935144040) which is now via an automatic update.

ALSO READ: This user 'hacked' Google Maps traffic flow in an entire area with 99 smartphones

For the study, the researchers focused on the Philips Hue smart bulbs and bridge, and found vulnerabilities (CVE-2020-6007) that enabled them to infiltrate networks using a remote exploit in the ZigBee low-power wireless protocol that is used to control a wide range of IoT devices.

The researchers used the Hue lightbulb as a platform to take over the bulbs' control bridge and ultimately, attacking the target's computer network. The more recent hardware generations of Hue lightbulbs do not have the exploited vulnerability, the study said.

ALSO READ: Facebook blames Apple for Amazon CEO Jeff Bezos' phone hack

"Many of us are aware that IoT devices can pose a security risk, but this research shows how even the most mundane, seemingly 'dumb' devices such as lightbulbs can be exploited by hackers and used to take over networks, or plant malware," said Yaniv Balmas, Head of Cyber Research, Check Point Research.

"It's critical that organisations and individuals protect themselves against these possible attacks by updating their devices with the latest patches and separating them from other machines on their networks, to limit the possible spread of malware. In today's complex fifth-generation attack landscape, we cannot afford to overlook the security of anything that is connected to our networks," Balmas said.

In an attack scenario that the researchers unravelled, the hacker controls the bulb's colour or brightness to trick users into thinking the bulb has a glitch. The bulb appears as 'unreachable' in the user's control app, so they will try to 'reset' it.

The only way to reset the bulb is to delete it from the app, and then instruct the control bridge to re-discover the bulb. The bridge discovers the compromised bulb, and the user adds it back onto their network.

ALSO READ: iPhone owners are 167 times more at risk of being hacked, next come Samsung owners

The hacker-controlled bulb with updated firmware then uses the ZigBee protocol vulnerabilities to trigger a heap-based buffer overflow on the control bridge, by sending a large amount of data to it.

This data also enables the hacker to install malware on the bridge - which is in turn connected to the target business or home network. The malware connects back to the hacker and using a known exploit (such as EternalBlue), they can infiltrate the target IP network from the bridge to spread ransomware or spyware.

"We recommend users to make sure that their product received the automatic update of this firmware version," Check Point said.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 05 Feb, 19:23 IST
Tags:

Sale

Mobiles Tablets Laptops
4% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹129,999₹134,999
Buy now
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
11% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹79,800₹89,900
Buy now
57% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹19,999₹47,000
Buy now
38% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹28,999
Buy now
20% OFF
Samsung Galaxy Tab S9 5G 256GB
  • Graphite
  • 8 GB RAM
  • 256 GB Storage
₹88,400₹110,998
Buy now
6% OFF
Apple iPad Pro 11 2022
  • Silver
  • 8 GB RAM
  • 128 GB Storage
₹105,999₹112,900
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
35% OFF
Asus ROG Strix G17 G713RM KH168WS Laptop
  • Eclipse Gray
  • 16 GB RAM
  • 1 TB SSD
₹164,990₹254,990
Buy now
22% OFF
Asus ROG Strix G15 G513RM HQ273WS Laptop
  • Green
  • 16 GB RAM
  • 1 TB SSD
₹70,990₹90,990
Buy now
42% OFF
Asus ROG Zephyrus G14 GA401QC HZ046TS Laptop
  • Eclipse Gray
  • 8 GB RAM
  • 1 TB SSD
₹89,990₹155,990
Buy now