Wind Vision Android App: Customer data at risk from hackers! Security vulnerabilities have been identified in the Wind Vision Android Application, a service from telecommunications provider Wind Hellas. The security flaws in the application allow the breach of legitimate user accounts as well as the theft of passwords and other accounts.
According to confidential information from a SecNews user, who sent an anonymous message with his identity hidden, the Wind Hellas application poses a risk to hundreds of Greek citizens who have the subscription service and use it on their personal devices. Four (4) critical vulnerabilities have already been identified in the application and while Wind Hellas was aware of it as early as November 14, 2020, there has been no official response/announcement or update on whether and if the security issue has been resolved.

Wind Vision is a digital television service offered by WIND Hellas, a Greek telecommunications provider, that allows the streaming of digital content. The Wind Vision mobile application, available for Android and iOS, allows users to watch television “on the go” from smartphone devices.
The Wind Vision Android app is available on the Google Play Store. The latest available version of the app (10.0.16) was found to be vulnerable to four security issues. The vulnerabilities could be combined to create a chain of attacks that would allow a malicious application orchestrated by hackers to compromise a victim user's account.
By hacking a legitimate account, the malicious user (hacker) could proceed to download and watch TV content by abusing the victim's subscription. The hacker also has the ability to block the legitimate subscriber's access to the application by changing the PIN code and replacing the registered devices. As a result, thousands of legitimate users can find themselves without access and lose all the money they have paid for their subscription. It is worth mentioning that the malicious user, taking advantage of the compromised accounts financially, may sell Dark Web all the passwords

The SecNews team must warn you about the greatest risk posed by a possible sale of passwords stolen from the Wind Vision Android Application. Specifically, those legitimate users who have chosen as the password for the subscription service a password that they already use in other services, government platforms (www.efka.gov.gr), social networking accounts (Facebook, Instagram, Twitter, TikTok , etc.) and electronic banking services (internet banking) there is a great risk of violation of these services in the event of a shared password. Great care, if you have the Wind Vision Android Application, immediately change your passwords as well as any other account you use shared credentials for.
Wind's IPTV infrastructure used Zappware's “Nexx4” solution. Zappware's cross-platform solutions for DVB, IPTV and OTT services are used by telecommunications providers operating in many countries, including Wind Hellas. Some of the providers are:
- A1 Croatia
- A1 Bulgaria
- A1 Slovenia
- Orange Belgium
- A1 Austria
- Trinidad and Tobago / Caribbean Amplia
Since the issues identified in the Wind Vision application affect Zappware's software, millions of users worldwide may be at risk.
Although Zappware has been repeatedly contacted in recent months (20/11/2020, 30/11/2020 and 22/12/2020) that the Wind Vision Android application has not been updated to include appropriate updates for the vulnerabilities discovered, it is not known whether the security vulnerabilities have been fixed at the time of writing this article.

It is deemed necessary to remediate serious security issues, such as those concerning the Wind Vision Android application, and priority should be given to the development of new features to safeguard user privacy and protect their accounts.
It should be emphasized that the vulnerabilities were responsibly disclosed to Zappware and Wind Hellas by the security researcher who identified the weakness, providing detailed instructions and remediation recommendations to assist in the remediation process.
Technical description of security gaps
The following section provides a brief overview of the vulnerabilities discovered as well as some technical details.
CVE-2021-22268 : Insecure Authentication
Wind Vision authenticated users via an Oauth2 “Authorisation Code” flow using a web browser.The chosen way of authenticating users was not secure as the assigned code could be intercepted by third-party applications and exchanged for a valid session token. This issue, combined with the URL compromise described below, allows the victim account to be taken over after initially tricking the user (usually through social engineering) into clicking on the wrong handler application.
CVE-2021-22269 : PIN Code Leakage
The "master PIN code" required by the application to configure certain settings was leaked during the application's communication with the servers. Therefore, it is possible to intercept the interception of the four-digit code through network traffic, as the application was not found to use certificate pinning.
CVE-2021-22270 : URL Hijacking
The Wind Vision application made insecure use of the URL-scheme Inter-Process Communication (IPC) mechanism offered by the Android operating system. The Deep Link implementation is susceptible to “URL Hijacking,” an attack that allows the launch of malicious third-party applications or the theft of sensitive data by tricking the user into accepting the wrong “handler” for a registered URL scheme.

CVE-2021-22268 : Reproducible Device ID
Wind Vision users can register a number of devices to their subscription, which are then tracked according to the locally generated Device ID. However, this generation process is easily hackable, as it does not use a random sequence. As a result, a valid device ID could be recreated by third-party applications running on the same device. If such malicious applications also maintain a valid session token, then they could issue valid requests against the Wind Vision server that has access to all user functions, including streaming TV content.
As other vulnerabilities were discovered (CVE-2021-22270, CVE-2021-22268) they could be connected to obtain a session token, combining the exploitation of this security gap leading to the breach of Wind Vision accounts.

SecNews is publishing this article to inform the public about such a serious security issue and to warn users who may be at risk from it. We assume that since the Zappware platform is third party, Wind should require an immediate fix from the vendor (vendor patch) since the vulnerability is valid at the time of writing.
Being a purely journalistic and informative website, our main goal is to immediately inform our users about key issues related to cybersecurity.
It should be noted that the security vulnerabilities were discovered following independent research by Leonidas Tsaousis (@laripping) of F-Secure Consulting.

*Disclaimer: SecNews has confirmed the reliability of the source. The research regarding the vulnerability has been carried out by security expert Leonidas Tsaousis and SecNews bears no responsibility for possible variations or modifications made after the publication of this article.
SecNews publishes the article for the protection of personal data of our readers and of society at large.
Additionally, SecNews' goal is for the company to become aware of the publication of the vulnerability on an international website so that it can take the necessary corrective actions (towards the Zappware platform provider) if they have not been taken so far.
