HomeSecurityCritical vulnerabilities identified in Telestar Digital GmbH IoT devices

Critical vulnerabilities identified in IoT devices Telestar Digital GmbH

Critical vulnerabilities have been discovered in Telestar Digital GmbH Internet of Things (IoT) radio devices that allow hackers to remotely compromise systems.

IoT

On Monday, researcher Bunjamin Kunz revealed the company's findings, which affected versions CVE-2019-13473 and CVE-2019-13474.

A few weeks ago, the company discovered an anomaly on a private server connected to web radio terminals belonging to Telestar devices, along with an atypical telnet server. The radios in question are from the company's Imperial & Dabman Series I and D product line, which includes portable radios and DAB stereos. These products are sold throughout Europe, use Bluetooth and Internet , and are based on the Debian Linux BusyBox.

An investigation into the radios revealed an undocumented Telnet service on Port 23, and because port forwarding was active, it could be handled externally. The video below shows how a port scan, the nmap tool, and ncrack could be used to penetrate the system.

The team was able to log into the radio in just 10 minutes due to lax password security, giving them root access with full privileges.

“For the test we edited some of the folders, created files and modified paths to see what we could change in the application,” says Kunz. “Finally, we were able to edit and access everything on the box and were able to completely compromise the Telestar Digital GmbH radio device.”

Possible attacks included changing device names, forcing playback streams, storing audio files as messages, and transmitting audio as commands both locally and remotely.

On Facebook, the security researcher stated that over a million devices may be at risk.

Telestar Digital GmbH

While hacking an IoT radio may not seem like a big security issue, the revelation highlights a problem that affects us all – the hacking of IoT devices to create larger threats. For example, variants of the Mirai bot specialize in hijacking IoT devices with open ports or weak security – such as those using default credentials – in order to launch powerful distributed denial of service (DDoS) attacks. It is also possible to exploit these vulnerabilities to spread malware.

The telnetd service has been changed and the use of the weak password has been revised. Automatic updates over Wi-Fi are now available and can be applied by setting affected devices to factory settings and accepting downloads of the latest firmware version.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS