Unveiling IoT Vulns: From Backdoors to Bureaucracy

Kai-Ching Wang, Chiao-Lin Yu

DEF CON 33 · Day 1 · Main Stage

Overview

This talk by Kai-Ching Wang and Chiao-Lin Yu, seasoned security researchers from Trend Micro and CHT Security in Taiwan, delves into the often-overlooked realm of manufacturer-created backdoors and inherent vulnerabilities within Internet of Things (IoT) devices. Moving beyond conventional hacking narratives, the presentation illuminates how many IoT devices ship with pre-existing, hidden access points, rendering traditional external attack mitigation insufficient. The speakers emphasize that these backdoors are not the result of malicious external actors but rather stem from debug features, legacy code, internal access mechanisms, or flawed update processes left behind by manufacturers.

Watch on YouTube

Visual summary for Unveiling IoT Vulns: From Backdoors to Bureaucracy by Kai-Ching Wang, Chiao-Lin Yu
Visual summary for Unveiling IoT Vulns: From Backdoors to Bureaucracy by Kai-Ching Wang, Chiao-Lin Yu

Key moments

  1. 0:00 Introduction: The hidden IoT backdoor problem
  2. 3:00 Methods for acquiring IoT device firmware
  3. 6:15 Real-world command injection vulnerability example
  4. 6:30 Uncovering manufacturer-built backdoors in IoT devices
  5. 7:00 Examples: Hardcoded passwords and hidden accounts
  6. 8:45 Open services and hidden Telnet backdoors
  7. 10:00 Exploiting hidden APIs and undocumented paths

Unveiling IoT Vulns: From Backdoors to Bureaucracy

Speakers: Kai-Ching Wang, Security Researcher, Trend Micro; Chiao-Lin Yu, R&D and Security Team Lead, CHT Security

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=L4cMPw2uDtc

Overview

This talk by Kai-Ching Wang and Chiao-Lin Yu, seasoned security researchers from Trend Micro and CHT Security in Taiwan, delves into the often-overlooked realm of manufacturer-created backdoors and inherent vulnerabilities within Internet of Things (IoT) devices. Moving beyond conventional hacking narratives, the presentation illuminates how many IoT devices ship with pre-existing, hidden access points, rendering traditional external attack mitigation insufficient. The speakers emphasize that these backdoors are not the result of malicious external actors but rather stem from debug features, legacy code, internal access mechanisms, or flawed update processes left behind by manufacturers.

The core of their research, spanning over 30 devices and leading to more than 50 CVEs, highlights a critical systemic flaw in the IoT ecosystem. Beyond the technical discovery of these vulnerabilities, the talk provides a stark look into the arduous and often frustrating process of responsible disclosure. It exposes how vendors frequently ignore, delay, or dismiss reported issues, citing reasons such as "end-of-life" status or internal-only fixes, leaving millions of devices at risk. This article will dissect their findings, offering a comprehensive technical deep dive into how these backdoors are uncovered and the profound implications for both cybersecurity professionals and everyday users.

The talk serves as a crucial wake-up call, demonstrating that securing IoT goes far beyond patching known exploits; it requires a fundamental shift in how devices are designed, manufactured, and supported. By shedding light on the bureaucratic hurdles faced during vulnerability reporting, Wang and Yu advocate for a collaborative approach involving manufacturers, governments, users, and researchers to foster a safer and more transparent IoT landscape. Their work underscores the urgent need for greater accountability and more robust security practices from the very inception of IoT product development.

Background

▶ Watch: Introduction: The hidden IoT backdoor problem (0:00)

The pervasive nature of Internet of Things (IoT) devices has introduced a new frontier in cybersecurity, often characterized by a focus on external threats and sophisticated hacking techniques. However, Kai-Ching Wang and Chiao-Lin Yu's research pivots this perspective, revealing a more insidious and fundamental problem: the widespread presence of manufacturer-built backdoors. These are not vulnerabilities introduced by external attackers, but rather inherent design flaws or intentional, yet poorly secured, access mechanisms embedded by the device creators themselves. The speakers contend that, for many IoT devices, the "backdoor is already open" from the moment they are deployed, requiring "no hacking needed."

This problem arises from several common practices in IoT development. Often, debug features are left active in production code, providing unintended access. Old code is reused without proper auditing, bringing along legacy vulnerabilities or forgotten access points. Features intended for internal assets or badly implemented update tools can also serve as backdoors if not properly secured or removed before product release. Furthermore, the practice of reusing code from other vendors can inadvertently propagate backdoors across different product lines and manufacturers. The sheer volume of their findings—over 50 CVEs across more than 30 devices—underscores the systemic nature of this issue rather than isolated incidents.

The researchers emphasize that the problem isn't always malicious intent but often stems from a lack of care, financial constraints, or rigid company policies. A significant challenge highlighted is the vendor's refusal to fix bugs in "end-of-life" products, even when millions of units remain online and vulnerable. This creates a dangerous landscape where users are unknowingly exposed to risks that manufacturers acknowledge but decline to address. The talk sets the stage for a deep dive into how these hidden backdoors are discovered and the subsequent, often frustrating, journey of responsible disclosure within a complex, global IoT ecosystem.

Key Findings

▶ Watch: Real-world command injection vulnerability example (6:15)

Kai-Ching Wang and Chiao-Lin Yu's extensive research unveiled a critical array of findings, primarily centered on the pervasive nature of manufacturer-introduced backdoors and the systemic failures in vulnerability disclosure processes.

Firstly, the most striking discovery was the prevalence of built-in backdoors across a wide range of IoT devices. These were not external hacks but rather intentional or accidental access points left by manufacturers. The researchers found that these backdoors often manifest as hardcoded super admin passwords, hidden user accounts (like the "Shinten" account named after a vendor's headquarters), or undocumented encryption keys (such as one derived from a famous Taiwanese slogan "dot board").

Secondly, their methodology for firmware acquisition proved crucial. They successfully extracted firmware through various means: direct downloads from official websites (often protected by simple encryption like 0x31 padding), intercepting OTA (Over-The-Air) updates by exploiting a lack of certificate verification or expired certificates, physically dumping firmware from devices via serial ports like U-boot (sometimes even with labeled TX/RX pins), or gaining Remote Code Execution (RCE) to extract firmware using tools like BusyBox and Netcat. A common RCE vector was command injection, often achieved with a simple semicolon, highlighting basic security flaws.

Thirdly, the specific types of exploitable backdoors were diverse:

  • Exposed Services: Many devices left services like UPnP, ADB (Android Debug Bridge), or Telnet openly accessible, sometimes directly to the internet, often without any authentication. They even found hidden APIs that could re-enable Telnet if it was initially disabled.
  • Hidden Web Interfaces and APIs: Undocumented CGI scripts or API paths were discovered, allowing access to sensitive functions or the download of full configuration files containing usernames, passwords, and other critical data. One device even had an API path explicitly named "backdoor."
  • Cloud Control Vulnerabilities: IoT devices using MQTT for cloud communication frequently embedded hardcoded MQTT usernames and passwords, sometimes transmitted in plaintext. Exploiting this could grant access to entire fleets of devices globally.
  • Covert Data Exfiltration: Some devices were found to secretly send sensitive data back to vendors without user knowledge, detectable only through network traffic analysis.

Finally, the talk highlighted severe challenges in vendor disclosure and remediation. Key issues included:

  • "End-of-Life" (EoL) Refusal: Vendors frequently refused to patch critical vulnerabilities in EoL products, even when tens of thousands of units remained online. An example involved a critical RCE bug in a Tabert device used in Taiwan government networks, where the vendor initially refused a fix, only issuing an advisory after public disclosure.
  • "Twin Brother" Problem: A critical finding was that vendors often only acknowledged and patched the specific model reported, ignoring other models running the exact same vulnerable firmware. This necessitated researchers filing new CVEs for each "twin brother" model.
  • Denial and Delay: Vendors sometimes denied the existence of a vulnerability or delayed responses for months, even years, effectively turning reported bugs into zero-days.
  • Internal-Only Fixes: Some vendors claimed vulnerabilities were fixed in internal release notes but refused to make these public, leaving users unaware and unprotected.
  • Non-Disclosure Agreements (NDAs): Vendors sometimes requested researchers to sign broad NDAs, effectively burying vulnerabilities instead of fixing them.

These findings collectively paint a picture of an IoT industry grappling with fundamental security design flaws and a broken disclosure ecosystem, placing users at significant and often unrecognized risk.

Technical Deep Dive

▶ Watch: Uncovering manufacturer-built backdoors in IoT devices (6:30)

The technical core of Kai-Ching Wang and Chiao-Lin Yu's research revolves around the meticulous process of firmware acquisition and subsequent reverse engineering to uncover hidden backdoors and vulnerabilities. Their methodology is comprehensive, targeting various stages of an IoT device's lifecycle and access points.

Firmware Acquisition Techniques:

  1. Official Website Downloads: The most straightforward method often involved downloading firmware updates directly from manufacturer websites. While vendors attempt to protect these, the researchers frequently found weak or custom encryption. For instance, they encountered firmware padded with repetitive 0x31 bytes, indicating a simple XOR cipher or similar trivial protection. This suggests a lack of robust cryptographic practices, making it relatively easy for an attacker to decrypt and analyze the firmware.
  1. Over-The-Air (OTA) Update Interception: Many IoT devices update their firmware wirelessly. The researchers employed SSL interception tools to capture OTA traffic. A recurring vulnerability here was the absence of proper certificate verification. Vendors often disable or bypass certificate validation to avoid issues with expired certificates on older devices or simply due to oversight. This allows an attacker to perform a man-in-the-middle (MitM) attack, intercepting the firmware, analyzing it, or even injecting malicious updates.
  1. Direct Device Firmware Dumping: When remote or OTA methods failed, physical access was key.
  • Serial Ports: Many devices expose serial debug ports like U-boot, often labeled TX (Transmit) and RX (Receive) pins. These provide direct access to the bootloader, allowing for firmware extraction or even command-line interaction.
  • Repair Engineer Marks: A clever technique involved sending a device for "repair." Repair engineers sometimes solder pins for debugging, leaving tell-tale solder marks that reveal hidden serial access points.
  • Bootloader Functions: Some bootloaders offer explicit import/export functions that can be leveraged to retrieve the firmware image.
  1. Remote Code Execution (RCE) for Firmware Extraction: Gaining RCE on a device significantly simplifies firmware acquisition. The researchers utilized common Linux utilities like BusyBox or Netcat to dump firmware directly from the device's file system or upload custom scripts for analysis. The initial RCE itself was often achieved through command injection, a vulnerability still prevalent in 2024 (as noted by the speakers). Simple input fields or network parameters vulnerable to characters like a semicolon (;) could allow an attacker to execute arbitrary commands, including those to extract firmware.

Backdoor Discovery and Exploitation:

Once firmware was obtained, reverse engineering revealed a multitude of backdoors:

  1. Hardcoded Credentials and Hidden Accounts:
  • Super Admin Passwords: Devices often contained hardcoded passwords that users couldn't change, providing persistent, privileged access.
  • Hidden User Accounts: The researchers found accounts not visible in the user interface or documentation. A notable example was an account named "Shinten," which was the name of the vendor's headquarters, suggesting an internal debug or management account.
  • Password Algorithms: They frequently found the password hashing or encryption algorithms directly within the firmware, negating the need for brute-forcing.
  • Hardcoded Encryption Keys: One humorous but alarming instance involved an encryption key that was a slogan from a famous Taiwanese form called "dot board," highlighting a severe lack of cryptographic hygiene.
  1. Exposed and Undocumented Services:
  • UPnP (Universal Plug and Play): Many devices exposed UPnP ports without authentication, sharing excessive information or functionality directly to the internet.
  • ADB/Telnet: Services like ADB (often left on by mistake during manufacturing) and Telnet were found running, even when vendors claimed they were disabled. The talk mentioned finding Telnet passwords hardcoded in plain text within associated mobile applications, emphasizing the need to analyze the entire "ecosystem."
  • Hidden APIs to Re-enable Services: Even if a service like Telnet was initially closed, the researchers discovered hidden API calls that could re-enable it, demonstrating a persistent backdoor mechanism.
  1. Hidden Web Interfaces and Configuration Exposure:
  • Hidden CGI Scripts: Beyond standard web interfaces, undocumented CGI scripts provided access to sensitive functions.
  • Undocumented API Paths: Reverse engineering revealed API paths not linked in any documentation. These paths often allowed the download of full configuration files containing sensitive information like usernames, passwords, and network settings. Alarmingly, one device had an API path explicitly named "backdoor" in plaintext.
  1. Cloud Control (MQTT) Vulnerabilities:
  • Many IoT devices use MQTT for communication with cloud platforms. The researchers frequently discovered hardcoded MQTT usernames and passwords within the device firmware. These credentials were sometimes sent in plaintext, allowing an attacker to subscribe to all topics and gain access to data from, and potentially control over, vast numbers of devices globally.
  1. Covert Data Exfiltration:
  • Beyond explicit backdoors, some devices were found to secretly send sensitive data back to the vendor without user consent or knowledge. This behavior was only detectable by monitoring network traffic, highlighting the importance of comprehensive network analysis in IoT security assessments.

The combination of these technical findings illustrates that IoT security is not just about defending against external attacks, but fundamentally about scrutinizing the internal design and implementation choices made by manufacturers, which often introduce critical vulnerabilities from the outset.

Demo / Proof of Concept

▶ Watch: Open services and hidden Telnet backdoors (8:45)

While the talk provided detailed explanations and real-world examples of vulnerabilities discovered, the presentation itself did not feature a live, interactive demonstration or a dedicated "Proof of Concept" section in the traditional sense. Instead, the speakers illustrated their findings through captured screenshots of code snippets, network traffic, and system outputs. For instance, they showed an example of a firmware's 0x31 padding for encryption, a captured OTA update showing traffic, a command injection using a semicolon, and the discovery of a hidden "Shinten" user account. These visual aids served as concrete evidence of the vulnerabilities and the methods used to uncover them, effectively functioning as static proofs of concept embedded within the technical deep dive and key findings sections. The focus was primarily on conveying the methodology and the sheer volume of issues rather than an interactive exploit demonstration.

Defensive Implications

▶ Watch: Exploiting hidden APIs and undocumented paths (10:00)

The findings presented by Kai-Ching Wang and Chiao-Lin Yu carry profound defensive implications for all stakeholders in the IoT ecosystem. A multi-faceted approach is required to mitigate the risks posed by manufacturer-built backdoors and improve the vulnerability disclosure process.

For Manufacturers:

  • Secure Design Principles: Implement security-by-design from the outset. This means avoiding hardcoded credentials, hidden accounts, and undocumented debugging interfaces in production firmware.
  • Transparent Documentation: If debug or service ports are necessary for maintenance, they must be clearly documented and protected with robust authentication and access controls, not hidden.
  • Robust Development Lifecycle: Adopt secure coding practices to prevent common vulnerabilities like command injection. Implement strict code reviews and security testing throughout the product lifecycle.
  • Responsible Disclosure Program: Establish a clear, accessible, and responsive vulnerability disclosure program. Respond to researchers promptly, acknowledge findings, and provide timely patches and public advisories, even for "end-of-life" products where feasible.
  • Comprehensive Patching: When a vulnerability is identified, vendors must ensure that all affected models and firmware versions are covered, addressing the "twin brother" problem.
  • No NDAs for Vulnerabilities: Refrain from using broad NDAs that suppress vulnerability disclosure; instead, foster collaboration with researchers.

For Government and Regulatory Bodies:

  • Mandate Transparency: Enforce regulations that require manufacturers to list all service and debug ports and disclose any hidden access mechanisms.
  • Prohibit Hidden Backdoors: Implement laws or standards that explicitly prohibit hidden backdoors and hardcoded, unchangeable credentials in consumer and enterprise IoT devices.
  • Support Vulnerability Reporting: Create and support independent channels for reporting IoT vulnerabilities, similar to how MITER stepped in for Zel, to ensure issues are addressed even when vendors are unresponsive.
  • Education and Awareness: Invest in educating both IoT developers and consumers about security best practices and the risks of insecure devices.
  • International Cooperation: Given the global nature of IoT supply chains, foster international collaboration on security standards and enforcement.

For Users:

  • Informed Purchasing: Prioritize purchasing IoT devices from vendors with a demonstrated commitment to security, transparent patching policies, and active vulnerability disclosure programs.
  • Firmware Updates: Always keep device firmware updated to the latest version. While not all vendors release patches, it's the primary way users can receive fixes.
  • Network Segmentation: Isolate IoT devices on a separate network segment or VLAN to limit their access to sensitive internal networks.
  • Monitor Network Traffic: Advanced users can monitor their IoT devices' network traffic for unusual or unauthorized data transmissions.
  • Report Anomalies: Report any strange behavior, hidden features, or suspected vulnerabilities to the vendor or relevant security researchers/organizations.

For Security Researchers:

  • Thorough Analysis: Continue to look for hidden backdoors, undocumented APIs, and insecure channels within IoT devices and their entire ecosystem (device, cloud, mobile app).
  • Responsible Disclosure: Adhere to responsible disclosure principles, prioritizing user safety and privacy. Give vendors a reasonable chance to fix issues before public disclosure.
  • Advocacy and Collaboration: Work with vendors, government, and user communities to advocate for better security practices and systemic changes in the IoT industry. Help raise awareness about the risks of poor maintenance and inadequate vulnerability response.

Ultimately, defending against these pervasive issues requires a fundamental shift towards greater transparency, accountability, and collaboration across the entire IoT landscape.

Key Takeaways

  • Ubiquitous Manufacturer Backdoors: Many IoT devices ship with built-in, hidden backdoors and hardcoded credentials, often due to debug features, legacy code, or poor security practices, requiring no external hacking to exploit.
  • Broken Vulnerability Disclosure: The process of reporting vulnerabilities to vendors is severely flawed, characterized by delays, denials, "end-of-life" excuses, internal-only fixes, and even attempts to suppress disclosure through NDAs.
  • The "Twin Brother" Problem: Vendors frequently only patch or acknowledge the specific model reported, ignoring other devices running the exact same vulnerable firmware, necessitating repeated reporting and CVE issuance for identical flaws.
  • Comprehensive Ecosystem Analysis is Critical: Securing IoT devices requires examining the entire ecosystem, including firmware, mobile applications (which may contain hardcoded passwords), cloud communication (e.g., insecure MQTT), and network traffic for hidden data exfiltration.
  • Systemic Change is Imperative: Improving IoT security demands a collaborative effort from manufacturers (designing securely, clear disclosure), governments (enforcing standards, supporting reporting), users (informed choices, updates), and researchers (responsible discovery and advocacy).
  • Basic Security Flaws Persist: Fundamental vulnerabilities like command injection via a simple semicolon, lack of certificate verification in OTA updates, and plaintext credential storage are still prevalent in modern IoT devices.

About the Speaker(s)

Kai-Ching Wang, also known as Steven, is a security researcher at Trend Micro, based in Taiwan. His work focuses on IoT security, and he is actively involved in discovering and reporting vulnerabilities in a wide range of connected devices. He has a history of sharing his research at various international security conferences.

Chiao-Lin Yu, known as Canver Wang, leads the R&D and security team at CHT Security in Taiwan. Like Kai-Ching Wang, his expertise lies in IoT security, and he has presented their joint research at numerous conferences globally. Both speakers hail from Taiwan, a significant hub for IoT device manufacturing, giving them unique insights into the industry's security challenges. Their collaborative efforts highlight a shared commitment to improving the security posture of the IoT ecosystem.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent IoT firmware research with genuine legwork behind it — 30+ devices, 50+ CVEs, real methodology — but nothing here redefines the space. The disclosure dysfunction narrative is the more interesting contribution, though it's undercut by a format that reads more like a survey than a surgical dissection of any single vulnerability class.

Heather Calloway (CISO) — SOLID

Credible, evidence-backed IoT research with real scale — 30+ devices, 50+ CVEs — that lands hardest on the disclosure dysfunction rather than the vulnerabilities themselves. The technical findings are solid, but the talk stays in researcher mode and never fully crosses into the institutional accountability conversation that would make it matter to the people who can actually fix the ecosystem.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33