SkyBridge, SkySpider IoT devices under active attack
Seiko Solutions' SkyBridge IoT routers and SkySpider Wi-Fi access points contain vulnerabilities being actively exploited, enabling system compromise, data theft, and arbitrary command execution.
Japan's IPA (Information-Promotion Agency) has issued a security alert regarding multiple vulnerabilities in Seiko Solutions' network infrastructure products. The affected products include SkyBridge LTE-enabled IoT routers and SkySpider PoE-compatible Wi-Fi access points. These vulnerabilities allow malicious third parties with access to the web configuration interface to execute attacks including system destruction, data theft and tampering, and arbitrary execution of built-in commands.
Active exploitation of these vulnerabilities has already been confirmed in the wild, prompting IPA to recommend immediate firmware updates. The vendor has released patched versions addressing these security issues. However, according to the product developer, some vulnerabilities cannot be fully resolved through firmware updates alone, requiring additional mitigation measures to be implemented alongside the patches.
Organizations using these devices should consult the vendor's security advisories for detailed remediation guidance and implement both firmware updates and recommended workarounds as soon as possible to protect against ongoing exploitation attempts.
Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2023/alert20230830.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free