Bishop Fox found four critical zero day flaws in the $20 YoLink Smart Hub that can give attackers remote control of smart locks and other access points. If you rely on a cheap gateway to manage physical entry, that hub becomes a single point of failure, so treat it as untrusted until YoSmart issues patches.
TL;DR
🔐 Authorization bypass allows remote control
📡 MQTT traffic is unencrypted and exposes credentials
📂 Session flaws let attackers maintain access
⚠️ Disconnect the hub from critical systems until patched
https://hackread.com/20-yolink-iot-gateway-vulnerabilities-home-security/
#IoT #IoTSecurity #Vulnerability #YoLink #security #privacy #cloud #infosec #cybersecurity
🚨 Researchers find four zero-day vulnerabilities in the $20 #YoLink IoT gateway, exposing smart locks and home access to remote attackers 🔓🔌
Read: https://hackread.com/20-yolink-iot-gateway-vulnerabilities-home-security/
#IoTsecurity #SmartHome #Cybersecurity #Vulnerability #HomeSafety