Ikea Smart Light System Flaw Lets Attackers Turn Bulbs on Full BlastIkea Smart Light System Flaw Lets Attackers Turn Bulbs on Full Blast
With just one malformed Zigbee frame, attackers could take over certain Ikea smart lightbulbs, leaving users unable to turn the lights down.
October 5, 2022
Researchers have demonstrated how an attacker could take over control of light bulbs in the Ikea Trådfri smart lighting system, ultimately turning the bulbs up to full brightness — and users can't turn them down through the app or the remote control.
Cybersecurity analysts at Synopsys CyRC found that if a threat actor re-sent the same malformed Zigbee frame (IEEE 802.15.4) over and over again, an attacker could advantage of two vulnerabilities (tracked under CVE-2022-39064 and CVE-2022-39065) in the Ikea Trådfri smart lighting system.
"The malformed Zigbee frame is an unauthenticated broadcast message, which means all vulnerable devices within radio range are affected," the Synopsys report explained.
The result of the Internet of things (IoT) security flaw is a lighting system factory reset where the user is stripped of control over their bulbs both through the Ikea Smart Home application as well as the companion Trådfri remote control, Syopsys added. It starts with a flicker and then leaves the lights on full, permanently.
"To recover from this attack, a user could manually power cycle the gateway," the team said. "However, an attacker could reproduce the attack at any time."
Synopsys disclosed the smart lighting vulnerabilities to Ikea in June 2021 and Ikea released a fix in February 2022, the report added.
About the Author(s)
Hacking Your Digital Identity: How Cybercriminals Can and Will Get Around Your Authentication MethodsOct 26, 2023
Modern Supply Chain Security: Integrated, Interconnected, and Context-DrivenNov 06, 2023
How to Combat the Latest Cloud Security ThreatsNov 06, 2023
Reducing Cyber Risk in Enterprise Email Systems: It's Not Just Spam and PhishingNov 01, 2023
SecOps & DevSecOps in the CloudNov 06, 2023
9 Traits You Need to Succeed as a Cybersecurity Leader
The Ultimate Guide to the CISSP
Get the Gartner Report: SOC Model Guide
The Evolving Ransomware Threat: What Business Leaders Should Know About Data Leakage
Building Immunity: The 2021 Healthcare and Pharmaceutical Industry Cyber Threat Landscape Report