QuoVadis Posted July 27, 2016 Report Posted July 27, 2016 Security researchers have discovered nine vulnerabilities in a range of internet-connected light bulbs made by Osram. The flaws in the Lightify products could give attackers access to a home wi-fi network, and potentially operate the lights without permission. Osram said a "majority" of the problems would be fixed in a software update in August, but four remained unpatched. One security expert said Osram had made an "elementary" mistake. Osram's Lightify range features internet-connected light bulbs that can be controlled using a smartphone app. Researcher Deral Heiland from Rapid7 discovered nine vulnerabilities in the Home and Pro range and reported them to the manufacturer. One problem was that the Osram smartphone app stored an unencrypted copy of the user's wi-fi password. That could give an attacker access to a user's home wi-fi network and the devices connected to it, if the password was extracted from the app. Full article: http://www.bbc.co.uk/news/technology-36903274 https://community.rapid7.com/community/infosec/blog/2016/07/26/r7-2016-10-multiple-osram-sylvania-osram-lightify-vulnerabilities-cve-2016-5051-through-5059 Quote