Your Bulb Has Trust Issues

Loading...
Thumbnail Image

Contributor

Advisor

Editor

Performer

Department

Instructor

Depositor

Speaker

Researcher

Consultant

Interviewer

Interviewee

Narrator

Transcriber

Annotator

Journal Title

Journal ISSN

Volume Title

Publisher

Journal Name

Volume

Number/Issue

Starting Page

7121

Ending Page

Alternative Title

Abstract

Your smart bulb might be lighting up your room, but it could also be lighting up vulnerabilities in your network. As smart homes are filled with IoT devices, security often takes a backseat to convenience, especially with popular open-source firmware like Tasmota. This research investigates how a malicious actor who has access to a vulnerable local network device could hijack a Tasmota-flashed smart bulb. By changing web console and WiFi credentials, the attacker could virtually block the owner's access to their device. Through a series of scripted payloads, the study considered credential persistence, exploit efficiency, and the impact of scaling up device counts. The results show that with minimal effort, attackers can persistently compromise smart bulbs, revealing a critical gap in home network security. These findings show a clear proof-of-concept for low-complexity lateral movement attacks on IoT devices, underscoring the need for stronger local network defenses and smarter firmware defaults.

Description

Citation

Extent

10 pages

Format

Type

Conference Paper

Geographic Location

Time Period

Related To

Proceedings of the 59th Hawaii International Conference on System Sciences

Related To (URI)

Table of Contents

Rights

Attribution-NonCommercial-NoDerivatives 4.0 International

Rights Holder

Catalog Record

Local Contexts

Email libraryada-l@lists.hawaii.edu if you need this content in ADA-compliant format.