The ecobee3 lite hardware board contains a Universal Asynchronous Receiver/Transmitter (UART) interface on the application board that allows a threat actor to access a password-protected interactive shell. The password for the shell can be recovered through firmware reverse engineering, allowing a threat actor to gain underlying operating system access to the device.
The ecobee3 lite device has the UART interface obscured on the PCB board. The research team connected to the serial/UART interface using a USB-to-serial adapter.
The team was able to intercept autoboot using the discovered root password and subsequently gain console access to the full device.