ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-558: (Pwn2Own) Amazon Smart Plug OTA Update Process Improper Certificate Validation Vulnerability

mediumAdvisoryimportance 22
AI summary · glm-5.3-flash

ZDI disclosed a Pwn2Own certificate validation flaw (CVSS 6.8) in Amazon Smart Plug's OTA process, allowing network-adjacent attackers to bypass update verification.

The Zero Day Initiative published ZDI-26-558 for an improper certificate validation flaw in the Amazon Smart Plug OTA update process, demonstrated at Pwn2Own. Network-adjacent attackers need no authentication to bypass certificate validation for over-the-air updates. ZDI rated the issue CVSS 6.8.

  • Improper certificate validation lets network-adjacent attackers bypass OTA update verification.
  • No authentication required; ZDI assigned CVSS 6.8.
Full article

This vulnerability allows network-adjacent attackers to bypass certificate validation for OTA updates on affected installations of Amazon Smart Plug. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8.

This source does not provide full text. Read it at zerodayinitiative.com.