# SkyBridge, SkySpider routers hit by active exploits

Published: 2023-08-29 · Severity: high · Sectors: telecommunications, infrastructure
Canonical: https://vorant.io/reports/5f640b53-37e0-5eb6-b611-86ceccdd8451/skybridge-skyspider-routers-hit-by-active-exploits

> Seiko Solutions' SkyBridge IoT routers and SkySpider Wi-Fi access points have vulnerabilities already being exploited in the wild, IPA warns.

Japan's IPA issued an alert on vulnerabilities affecting Seiko Solutions' SkyBridge LTE IoT routers and SkySpider PoE Wi-Fi access points. An attacker with access to the web configuration interface could exploit these flaws to attack or destroy the device, steal or tamper with data, and execute arbitrary built-in commands.

IPA states that exploitation of these vulnerabilities has already been confirmed in the wild, and urges affected organizations to update firmware to the latest versions provided by the vendor as soon as possible. Notably, the vendor has indicated that patching alone does not fully resolve some of the vulnerabilities, and recommends additional mitigations be applied per vendor guidance.

No specific CVE identifiers, threat actor attribution, or technical indicators were provided in this alert. Organizations using these devices should consult Seiko Solutions' official advisories for detailed remediation and workaround instructions.

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2023/alert20230830.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/5f640b53-37e0-5eb6-b611-86ceccdd8451/skybridge-skyspider-routers-hit-by-active-exploits.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
