SkyBridge, SkySpider routers hit by active exploits
Seiko Solutions' SkyBridge IoT routers and SkySpider Wi-Fi access points have vulnerabilities already being exploited in the wild, IPA warns.
Japan's IPA issued an alert on vulnerabilities affecting Seiko Solutions' SkyBridge LTE IoT routers and SkySpider PoE Wi-Fi access points. An attacker with access to the web configuration interface could exploit these flaws to attack or destroy the device, steal or tamper with data, and execute arbitrary built-in commands.
IPA states that exploitation of these vulnerabilities has already been confirmed in the wild, and urges affected organizations to update firmware to the latest versions provided by the vendor as soon as possible. Notably, the vendor has indicated that patching alone does not fully resolve some of the vulnerabilities, and recommends additional mitigations be applied per vendor guidance.
No specific CVE identifiers, threat actor attribution, or technical indicators were provided in this alert. Organizations using these devices should consult Seiko Solutions' official advisories for detailed remediation and workaround instructions.
Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2023/alert20230830.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free