IoT & Hardware

Hardware / Firmware Exposure

Information Disclosure

Hardcoded AES 256 bit key used in Kankun Smart socket and its mobile App

Hardcoded AES 256 bit key used in Kankun Smart socket and its mobile App.

6.8
/ 10
Medium
CVSS v2.0
ADVISORY ID
PS2
PUBLISHED
2022-10-02
CVE IDs
CVE-2015-4080
VENDORS
ikonke.com
PUBLIC EXPLOIT
None indexed
CWE
CWE-310
PRODUCT
Kankun Smart Socket
CVSS VECTOR
AV:N/AC:M/Au:N/C:P/I:P/A:P
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Hardcoded AES 256 bit key used in Kankun Smart socket and its mobile App.

The kankun smart socket device and the mobile app use a hardcoded AES 256 bit key to encrypt the commands and responses between the device and the app. The communication happens over UDP. An attacker on the local network can use the same key to encrypt and send unsolicited commands to the device and hijack it.

Vulnerability details

Vulnerability details

CVE-2015-4080
CWE-310
Medium | 6.8

Hardcoded AES 256 bit key used in Kankun Smart socket and its mobile App. The kankun smart socket device and the mobile app use a hardcoded AES 256 bit key to encrypt the commands and responses between the device and the app.

Auth:
None (remote)
Impact:
Partial data disclosure, partial integrity loss, partial denial of service
DISCLOSURE

Disclosure timeline

2015-05-25 Reported to Vendor, no response.

2015-05-29 Reminder sent to vendor, no response.

2015-06-05 Public disclosure.

References

Credits

Aseem Jakhar