ZDI-26-558: (Pwn2Own) Amazon Smart Plug OTA Update Process Improper Certificate Validation Vulnerability
This vulnerability allows network-adjacent attackers to bypass certificate validation for OTA updates on affected installations of Amazon Smart Plug. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-558?
ZDI-26-558 has a CVSS rating of 6.8, which indicates a medium severity risk.
How do I fix ZDI-26-558?
To mitigate ZDI-26-558, ensure that your Amazon Smart Plug is updated with the latest firmware provided by Amazon.
What types of attacks can exploit ZDI-26-558?
ZDI-26-558 can be exploited by network-adjacent attackers to perform unauthorized Over-The-Air (OTA) updates.
What is the impact of ZDI-26-558?
The impact of ZDI-26-558 includes potential unauthorized modifications to the device without proper authentication.
Which devices are affected by ZDI-26-558?
ZDI-26-558 affects installations of the Amazon Smart Plug that utilize the vulnerable OTA update process.