Russian security Vladislav Yarmak revealed yesterday that there is a backdoor mechanism in HiSilicon chips, which are embedded in millions of smart devices around the world (e.g. security cameras, DVRs, NVRs, etc.).
No fix has been released yet , as Yarmak did not inform HiSilicon of the security issue. As he said, he does not trust the company 's ability to properly patch the backdoor.
Yarmak published a report on Habr, which contains a detailed analysis of the backdoor. According to the expert, it is a combination of four old bugs/backdoors that were discovered in March 2013, March 2017, July 2017, and September 2017.
“Apparently, all these years HiSilicon has been unwilling or unable to provide adequate security fixes for the same backdoor, which, incidentally, was implemented intentionally,” Yarmak said.
How does the backdoor work?
According to the security researcher, an attacker can exploit the backdoor by sending a series of commands, via TCP port 9530, to devices using HiSilicon chips.
These commands will enable the Telnet service on the vulnerable device.
Yarmak says that once the Telnet service is installed, the attacker can connect with one of the following Telnet credentials and gain access to a root account, thus gaining full control of the vulnerable device.
![]()
These Telnet logins had been found in previous years as "hardcoded" in the firmware of HiSilicon chips, but according to Yarmak the company did nothing about them.
Proof-of-concept code
As mentioned above, Yarmak doesn't trust HiSilicon, so he didn't inform them about the security issue. So, there's no patch. However, the researcher created proof-of-concept (PoC) code that can be used to check whether a "smart" device works with the HiSilicon system on-chip (SoC) and whether the SoC is vulnerable to the type of attack mentioned above.
If a device is vulnerable, equipment replacement should be performed
“Given previous fake fixes for this backdoor, it is unwise to expect firmware security fixes from the company,” Yarmak said. “Owners of such devices should consider finding alternative solutions.”.
In case the owners of the vulnerable devices cannot afford to change equipment, they should “access network to these devices so that only trusted users can access them”, especially on ports 23/tcp, 9530/tcp, 9527/tcp (which can be used in attacks).
The proof-of-concept code is available on GitHub. Instructions are in the researcher's post on Habr.
