← Back to all advisories
Unranked

Hard-coded Default Root Credentials for All ecobee3 lite Devices

Advisory ID
L9-15-160
Category
Global Default Credentials
Vendor
ecobee
Product
ecobee3 lite
Affected Version
4.5.81.200
First Published
June 28, 2021
Last Updated
January 22, 2024
Impact
Unranked

Risk Summary

Hard-coded default root credentials exist across all devices, potentially allowing a threat actor to gain privileged access to the ecobee3 lite device. The root passwords reserved for admin users can be discovered through analysis of the compiled firmware via reverse engineering. The password is stored in a hash format but lacks complexity and can be easily brute-forced. Using the cracked password, a threat actor can gain access to the serial console on the device to extract sensitive information or modify the device.

Technical Details

The research team extracted the root credentials from the contents of the NAND flash. The credentials were cracked using brute-force techniques and used to gain access to the password-protected serial console.

Questions

Common questions about the ecobee3 lite default root credentials.

What is the hard coded root credential issue on the ecobee3 lite?

Hard coded default root credentials exist across all ecobee3 lite devices, which can give a threat actor privileged access. Advisory L9-15-160 covers version 4.5.81.200 and lists the category as Global Default Credentials. The root passwords reserved for admin users can be discovered by reverse engineering the compiled firmware.

Are the ecobee3 lite root credentials the same on every device?

Yes. The advisory describes hard coded default root credentials that exist across all ecobee3 lite devices rather than a password unique to each unit. That is why the finding is filed under the category Global Default Credentials, against version 4.5.81.200.

How were the ecobee3 lite root credentials recovered?

The research team extracted the root credentials from the contents of the NAND flash, then cracked them with brute force techniques. The advisory notes the password is stored as a hash but lacks complexity, so it can be brute forced easily. The cracked password opened the password-protected serial console.

What can an attacker do with the ecobee3 lite root password?

The advisory states that a threat actor using the cracked password can reach the serial console on the ecobee3 lite to extract sensitive information or modify the device. Impact is listed as Unranked. The advisory was first published on June 28, 2021 and last updated on January 22, 2024.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 Migration
Solutions
Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Subscription TestingAI-NativeFDA ComplianceVerified ExploitabilityELTON vs. Legacy TestingThreat-Led AI PentestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsAI NewsletterThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersPartnershipsContact Meet ELTON