Vulnerability In Xiaomi Electric Scooters Allows Attackers to Access The Machine
Electric scooters have proved to be a comfortable form of travel for few over short distances. Security researchers have highlighted other problem. As founded, Xiaomi electric scooters bear serious vulnerabilities. Exploiting the vulnerability could allow an attacker to remotely hack the scooters and execute commands, such as sudden breaks.
A researcher Rani Idan from Zimperium has found a serious vulnerability in Xiaomi electric scooters. As per his findings, the vulnerability could allow an attacker to take access of the machine. A successful remote access could then result in sudden breaking or acceleration.
“According our research, we determined the password is not being used properly as part of the authentication process with the scooter and that all commands can be executed without the password.”
Precisely, the scooters doesn't track of the authentication state as the password validation takes place at the application side only. As per result, it becomes easy for an attacker to exploit the vulnerability by sending any malicious payload to execute desired commands. The attacker in case present anywhere within proximity of 100 meters from the target device.
A Temporary Mitigation Might Help
The researcher confirmed that he has disclosed the vulnerability responsibly. However, Xiaomi has not patched the vulnerability yet despite knowing about the bug since January 28, 2019. Even in their acknowledgment to the researcher, they confirmed their knowledge of the vulnerability. The researcher suggests users connect the Xiaomi application to their mobiles before riding, as a temporary mitigation.
"Once your mobile connected and kept connected to the scooter an attacker won't able to remotely flash malicious firmware or lock your scooter"

Comments
Post a Comment