
A security researcher from Russia managed to gain access to Xiaomi electronic pet feeders around the world.
Last week, Anna Prosvetova, a security researcher from St. Petersburg, Russia, posted a series of messages on her personal Telegram , through which she stated that she had identified vulnerabilities in the back-end API and firmware of Xiaomi's FurryTail.
These are pet feeders that are connected to a app , through which pet owners can regulate the amount of food that will be available to their pet throughout the day.
Xiaomi FurryTail devices are specially designed to handle pet food and are often used when owners leave their pets alone at home or apartment when they need to go on a trip.
The researcher was able to locate 10,950 Furrytail feeders
Prosvetova said that while examining a device she bought from AliExpress for just $80, she found that its API allowed her to see all the other FurryTail devices operating around the world.
In total, he identified 10,950 devices, for which he claimed he could change feeding programs, without needing a password.
Additionally, he found that the devices also used an ESP8266 chipset for WiFi connectivity. He said a vulnerability in that chipset would allow an attacker to download and install new firmware and then reboot the feeders to change feeding amounts and times.
Prosvetova said the vulnerabilities could be exploited by hackers to use the animal feeders in an IoT DDoS botnet, as the entire process could be easily automated and executed on a large scale.
The researcher notified Xiaomi via email last week about her discovery. She then posted a screenshot of the company's response on her Telegram account, which admitted its mistake and promised to fix it.
It is unclear whether a patch for the flaw yet. A Xiaomi spokesperson also informed the researcher that she will not receive any compensation for her discovery, as the company does not have a vulnerability rewards program (VRP), unlike most major tech companies.
