Hard-coded default root credentials exist across all devices, potentially allowing a threat actor to gain privileged access to the ecobee3 lite device. The root passwords reserved for admin users can be discovered through analysis of the compiled firmware via reverse engineering. The password is stored in a hash format but lacks complexity and can be easily brute-forced. Using the cracked password, a threat actor can gain access to the serial console on the device to extract sensitive information or modify the device.
The research team extracted the root credentials from the contents of the NAND flash. The credentials were cracked using brute-force techniques and used to gain access to the password-protected serial console.
Hard coded default root credentials exist across all ecobee3 lite devices, which can give a threat actor privileged access. Advisory L9-15-160 covers version 4.5.81.200 and lists the category as Global Default Credentials. The root passwords reserved for admin users can be discovered by reverse engineering the compiled firmware.
Yes. The advisory describes hard coded default root credentials that exist across all ecobee3 lite devices rather than a password unique to each unit. That is why the finding is filed under the category Global Default Credentials, against version 4.5.81.200.
The research team extracted the root credentials from the contents of the NAND flash, then cracked them with brute force techniques. The advisory notes the password is stored as a hash but lacks complexity, so it can be brute forced easily. The cracked password opened the password-protected serial console.
The advisory states that a threat actor using the cracked password can reach the serial console on the ecobee3 lite to extract sensitive information or modify the device. Impact is listed as Unranked. The advisory was first published on June 28, 2021 and last updated on January 22, 2024.