Heimdal Security Blog

New IoT Bug Discovered in Devices Connected to Kalay Network

A new IoT bug was discovered that impacts devices that connect through the cloud platform named ThroughTek.

Products that make use of the Kalay network are the ones affected, counting to millions of them. Among these, we can name appliances from producers that engage in video surveillance solutions and IoT systems for home usage.

What Are the Characteristics of the New IoT Bug?

The ones who discovered this IoT bug were Mandiant’s Red Team experts back in 2020. This is now classified CVE-2021-28372, with a score no less than 9.6 out of 10.

According to the BleepingComputer publication, the characteristics of the new IoT bug, defined by researchers while investigating it together with ThroughTek and CISA are:

Mandiant observed that the binaries on IoT devices processing Kalay data typically ran as the privileged user root and lacked common binary protections such as Address Space Layout Randomization (“ASLR”), Platform Independent Execution (“PIE”), stack canaries, and NX bits.

Source

Researchers have tested this new IoT bug and they could identify and register devices by the method of a working development of Kalay protocol. They could also authenticate and connect to the remote customers or operate video information. Later on, a proof of concept code was built and what they managed with this was to impersonate a device on the Kalay network.

Image Source

What Mitigation Measures Experts Recommend

ThroughTek and Mandiant came with some mitigation measures.

ThroughTek released an updated security advisory of the 13th of August to mitigate the new IoT bug. They recommend:

In their report, Mandiant experts recommend that APIs with Kalay UIDs should have their security control checked one more time.

Of course, general mitigation measures remain also valid, such as ensuring you are up to date with your software and also that the password you use is a complex one, hard to guess. Avoiding mistrusted network connections when using an IoT device is also a best practice.