IoT & Hardware
Hardware / Firmware Exposure
Information Disclosure
Hardcoded AES 256 bit key used in Kankun Smart socket and its mobile App
Hardcoded AES 256 bit key used in Kankun Smart socket and its mobile App.
.png)
Overview
Hardcoded AES 256 bit key used in Kankun Smart socket and its mobile App.
The kankun smart socket device and the mobile app use a hardcoded AES 256 bit key to encrypt the commands and responses between the device and the app. The communication happens over UDP. An attacker on the local network can use the same key to encrypt and send unsolicited commands to the device and hijack it.
Vulnerability details
Hardcoded AES 256 bit key used in Kankun Smart socket and its mobile App. The kankun smart socket device and the mobile app use a hardcoded AES 256 bit key to encrypt the commands and responses between the device and the app.
Disclosure timeline
2015-05-25 Reported to Vendor, no response.
2015-05-29 Reminder sent to vendor, no response.
2015-06-05 Public disclosure.
References
2026-06-17 (NVD record)
Credits
Aseem Jakhar
















