Breaking News

LG Electronics Introduces World’s First Native 1000Hz Full HD Gaming Monitor Transcend to Showcase Next-Gen Storage Solutions at COMPUTEX 2026 Giga Computing Enhances Cloud Storage Solutions with AMD EPYC 8005 Server CPU SAMA S50 Rethinks Compact ATX Cases addlink’s 2026 Virtual Showcase

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Researchers Show How Networks Can Be Hacked from a Lightbulb

Researchers Show How Networks Can Be Hacked from a Lightbulb

Enterprise & IT Feb 5,2020 0

Security researchers showed how a threat actor could exploit an IoT network (smart lightbulbs and their control bridge) to launch attacks on conventional computer networks in homes, businesses or even smart cities.

Check Point’s researchers focused on the market-leading Philips Hue smart bulbs and bridge, and found vulnerabilities (CVE-2020-6007) that enabled them to infiltrate networks using a remote exploit in the ZigBee low-power wireless protocol that is used to control a wide range of IoT devices.

With the help of the Check Point Institute for Information Security (CPIIS) in Tel Aviv University, the researchers were able to take control of a Hue lightbulb on a target network and install malicious firmware on it. From that point, they used the lightbulb as a platform to take over the bulbs’ control bridge, and attacked the target network as follows:

  • The hacker controls the bulb’s color or brightness to trick users into thinking the bulb has a glitch. The bulb appears as ‘Unreachable’ in the user’s control app, so they will try to ‘reset’ it.
  • The only way to reset the bulb is to delete it from the app, and then instruct the control bridge to re-discover the bulb.
  • The bridge discovers the compromised bulb, and the user adds it back onto their network.
  • The hacker-controlled bulb with updated firmware then uses the ZigBee protocol vulnerabilities to trigger a heap-based buffer overflow on the control bridge, by sending a large amount of data to it. This data also enables the hacker to install malware on the bridge – which is in turn connected to the target business or home network.
  • The malware connects back to the hacker and using a known exploit (such as EternalBlue), they can infiltrate the target IP network from the bridge to spread ransomware or spyware.

The research was disclosed to Philips and Signify (owner of the Philips Hue brand) in November 2019. Signify confirmed the existence of the vulnerability in their product, and issued a patched firmware version (Firmware 1935144040) which is now available on their site.

In a joint decision with Signify, Check Point decided to postpone the release of the full technical details of the research in order to allow Philips Hue clients to have enough time to safely update their products to the latest version.

Tags: HackingSmart HomeCybersecurity
Previous Post
Spotify Reports Rise in Premium Subscribers
Next Post
Seagate Set to Launch 18TB HDDs in The First Half of the Calendar Year 2020

Related Posts

  • MSI has been hacked, be warned about where you download files

  • Hackers gain access to PS5 Debug Menu and show decrypted PS5 firmware files

  • HP Threat Research Shows Attackers Exploiting Zero‐Day Vulnerability Before Enterprises Can Patch

  • EA Gets hacked - 780GB of data and sourcecode stolen

  • European Supercomputers Researching Covid-19 Report Hacking Attacks

  • Intel Confirms "Thunderspy" Risk in Thuerbolt Devices

  • Microsoft Offers You $100,000 If You Can Hack the Linux-based Azure Sphere

  • Zoom Users' Data have Been on Sale on Dark Web: report

Latest News

LG Electronics Introduces World’s First Native 1000Hz Full HD Gaming Monitor
Consumer Electronics

LG Electronics Introduces World’s First Native 1000Hz Full HD Gaming Monitor

Transcend to Showcase Next-Gen Storage Solutions at COMPUTEX 2026
PC components

Transcend to Showcase Next-Gen Storage Solutions at COMPUTEX 2026

Giga Computing Enhances Cloud Storage Solutions with AMD EPYC 8005 Server CPU
Enterprise & IT

Giga Computing Enhances Cloud Storage Solutions with AMD EPYC 8005 Server CPU

SAMA S50 Rethinks Compact ATX Cases
Cooling Systems

SAMA S50 Rethinks Compact ATX Cases

addlink’s 2026 Virtual Showcase
PC components

addlink’s 2026 Virtual Showcase

Popular Reviews

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Soft2bet and the unseen hardware that makes instant play possible

Soft2bet and the unseen hardware that makes instant play possible

Endorfy Thock V2 Wireless Keyboard

Endorfy Thock V2 Wireless Keyboard

Crucial T710 2TB NVME SSD

Crucial T710 2TB NVME SSD

JSAUX 65Wh Rog Ally Battery

JSAUX 65Wh Rog Ally Battery

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed