Security News Samsung Smart TV pwnable over Wi-Fi Direct, pentester says

Solarquest

Moderator
Thread author
Verified
Staff Member
Malware Hunter
Well-known
Jul 22, 2014
2,525
Sammy says trust-known-MACs code is a feature not a bug
A security researcher is complaining that Samsung isn't making a serious response to a vulnerability in its Smart TVs.

The bug, discovered by pen-test outfit Neseso, concerns the televisions' implementation of Wi-Fi Direct authentication. An attacker only needs to sniff out the MAC address of a trusted device to connect to the TV. From there they potentially enjoy a jump-off point to a target's network.

Neseso says it's published its discovery at Full Disclosure because Samsung doesn't consider it a security risk.

The Smart TVs have a convenience feature so users don't have to authenticate every time they turn the TV on: trusted devices are instead whitelisted by MAC address. “The user will get notified about the whitelisted device connecting to the Smart TV, but no authentication [is] required”, the post states.

Since MAC addresses are easily sniffed over Wi-Fi and can also be spoofed, an attacker can impersonate the trusted device, get full access to the TV's features (including screen mirroring and remote control), and potentially access the network to which the TV is connected.

In the disclosure, Neseso says Wi-Fi Direct is enabled by default on the TVs, and switched on each time the TV is powered up – meaning a user would have to turn it off after each power-up.

Neseso says it first contacted Samsung in March, and was told early this month that the company “concluded that this is not a security threat”.
 

Winter Soldier

Level 25
Verified
Top Poster
Well-known
Feb 13, 2017
1,486
Neseso says it first contacted Samsung in March, and was told early this month that the company “concluded that this is not a security threat”.
Not a consistent and logical response from Samsung.
Simply, it was more honest to take note of the flaw working to resolve it.
But evidently, for Samsung the best way to solve problems is to ignore them!
 

Entreri

Level 7
Verified
May 25, 2015
342
IoT, the last thing on their mind, if they even consider it, is security.

On top of this, Samsung's quality and reliability has gone down the past several years.
 
  • Like
Reactions: Solarquest

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top