Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Netatmo Weather Stations Expose Wi-Fi Passwords: Researcher

Personal weather stations developed by Netatmo send Wi-Fi passwords and other information to the company’s servers in clear text, a researcher reported on Thursday.

Personal weather stations developed by Netatmo send Wi-Fi passwords and other information to the company’s servers in clear text, a researcher reported on Thursday.

Netatmo weather stations can be used to monitor indoor temperature, humidity, air quality and CO2 levels. The device also provides outdoor parameters such as temperature, relative humidity, air quality, barometric pressure, and weather. The devices are very popular, as shown by an interactive map available on the company’s website.Netatmo weather station

Johannes Ullrich, CTO of the SANS Internet Storm Center, tested one of these weather stations and discovered that after the initial setup, the device had sent his WPA password and the Wi-Fi network’s SSID to Netatmo’s servers unencrypted. This information is provided by the user when the device is configured via a custom application.

“Not only should data like this not be transmitted ‘in the clear’, but in addition, there is no need for Netatmo to know the WPA password for my network,” Ullrich said in a blog post.

Netatmo told the researcher that the contents of the weather station’s memory was collected at first startup for debugging purposes. The company says it has addressed the issue with the release of a firmware update, and has promised to remove the debug memory in the coming weeks.

In an email to SecurityWeek, Netatmo representatives said the weather stations no longer send debug information at installation time.

Internet of Things (IoT) security has made numerous headlines over the past period. A report published by HP last year revealed that 70% of IoT devices had been plagued by serious security flaws.

A report published by the company earlier this week on Internet-connected home security systems shows that many of these solutions can be easily accessed by malicious hackers due to the lack of proper protection mechanisms.

Advertisement. Scroll to continue reading.
Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Vulnerabilities

Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.

IoT Security

A vulnerability affecting Dahua cameras and video recorders can be exploited by threat actors to modify a device’s system time.