Security Flaws in IP Cameras and Routers Escalate IoT Hacking Threats

Honeywell, YI, CP Plus, and Others Affected
Remote Control and Account Theft Persist
Mandatory IoT Security Certification Urged
Stronger Vulnerability Checks and Management Needed

Photo Image
AI-generated image

Security vulnerabilities in IP cameras and routers that lead to account takeover and remote control continue to be discovered. As some products have actually been exploited in real-world hacking incidents, experts continuously stress the need to strengthen security verification, such as making Internet of Things (IoT) security certification mandatory.

According to the security industry on August 24, numerous security vulnerabilities and breach incidents involving foreign IP cameras and routers—including those from Honeywell, YI, CP Plus, Asus, and Shenzhen Zhibotong Electronics (Zbtlink)—are being reported consistently. The industry believes that a significant number of products from these manufacturers have been distributed in South Korea as well. Consequently, experts advise that mandatory certification or a strengthened management framework is necessary to verify minimum security standards before products enter the market.

At Honeywell, a vulnerability was discovered in the password recovery feature of certain closed-circuit television (CCTV) cameras, where the user's identity was not properly verified. Under this structure, an attacker could hijack accounts and camera footage by changing the account's recovery email without logging in.

In YI IP cameras, a vulnerability was found where the manufacturer hardcoded shared usernames and passwords into the firmware. In effect, a “master key” existed inside the device. Once these credentials are exposed, an attacker can gain access to all cameras running the firmware with the same vulnerability.

A similar issue occurred in products from another IP camera manufacturer, Shenzhen Liandian Communication Technology.

In CP Plus IP cameras, a vulnerability was confirmed where mechanisms to restrict access or lock accounts after repeated password attempts were insufficient. This creates an environment where an attacker can continuously try ID and password combinations using automated tools.

Photo Image
IP Camera and Router Vulnerability Cases

Routers commonly used in homes and offices were also found to be vulnerable to security risks.

Recently, 21 firmware versions of Shenzhen Zhibotong Electronics routers shocked the industry when a remote management function capable of executing external commands with administrator privileges was discovered. The routers communicated with an external server approximately every 35 seconds and could execute server commands with admin rights without separate verification.

Attacks actually exploiting vulnerabilities have also occurred. Most notably, last year, an incident was reported where more than 9,000 Asus routers were compromised by exploiting an existing vulnerability that allowed the execution of arbitrary system commands. Attackers created backdoors in the routers to maintain continuous access even after reboots or software updates.

As security vulnerabilities in smart devices such as IP cameras and routers are repeatedly exposed, the need to improve system frameworks to protect domestic consumers is growing. Security issues were confirmed not only in a few small and medium-sized brands, but also in products from market-leading companies that have been widely adopted in South Korea.

Photo Image
IoT Security Certification Cases

The IoT security certification introduced by the South Korean government in 2018 remains slow to take off because it is merely voluntary. In the first half of this year, the number of certifications stood at 37, less than half of last year's total of 106. While the government remains cautious on the grounds that mandatory certification could impose a financial burden on small and medium-sized enterprises, the reality is that even minimal safety measures fail to gain traction.

“To ensure that certification does not remain a mere formality, we should research ways to utilize AI agents to inspect actual vulnerabilities and reflect them in the certification,” said Kim Yong-dae, professor of electrical engineering at KAIST. “If we raise the level of security response by increasing domestic companies' participation in vulnerability disclosure and response frameworks (VDP/CVD), we can also encourage changes in foreign companies.”

· This article was translated using AI and was published after final review by the reporter.