IoT Security

Hackers Earn $350k on Second Day at Pwn2Own Toronto 2023

Smart speakers, printers, routers, NAS devices, and mobile phones were hacked on the second day at Pwn2Own Toronto 2023.

Smart speakers, printers, routers, NAS devices, and mobile phones were hacked on the second day at Pwn2Own Toronto 2023.

Hackers have earned roughly $350,000 in rewards after demonstrating successful exploits against a variety of devices on the second day of the Zero Day Initiative’s Pwn2Own Toronto 2023 competition.

Just as on the first day of the hacking contest, NAS devices, printers, smart speakers, and mobile phones were hacked on Wednesday, with successful exploits also demonstrated against routers.

The highest reward went to Chris Anastasio, who earned $100,000 for exploits targeting a vulnerability in the P-Link Omada Gigabit router and one in the Lexmark CX331adwe printer, ZDI announced.

On the second day of the competition, a Devcore intern earned $50,000 for a stack buffer overflow issue in the TP-Link Omada Gigabit router and two flaws in the QNAP TS-464 NAS device.

Team Orca of Sea Security also earned $50,000 on Wednesday, for a bug in the Synology RT6600ax router and a three-bug chain against the QNAP TS-464 NAS device.

Rewards of $30,000 were handed out for a command injection in the Wyze Cam v3 security camera and an out-of-bounds write issue in the Sonos Era 100 smart speaker.

ZDI also announced high rewards for an improper input validation bug and a permissive list of allowed inputs flaw in Samsung Galaxy S23 ($25,000), a stack-based buffer overflow issue in the HP Color LaserJet Pro MFP 4301fdw ($20,000), and a stack-based buffer overflow vulnerability in the Canon imageCLASS MF753Cdw printer ($10,000).

Additionally, multiple low-tier rewards were handed out for exploits targeting known vulnerabilities in QNAP TS-464, Wyze Cam v3, Synology BC500, and Canon imageCLASS MF753Cdw.

Advertisement. Scroll to continue reading.

Overall, ZDI says, participating hackers have earned more than $800,000 in rewards on the first two days of the competition, which is set to conclude on Friday.

Related: Hackers Earn $400k on First Day at Pwn2Own Toronto 2023

Related: Over $1 Million Offered at New Pwn2Own Automotive Hacking Contest

Related: Hackers Earn $180,000 for ICS Exploits at Pwn2Own Miami 2023

Related Content

Vulnerabilities

Google pushes a new Chrome update to patch another zero-day vulnerability demonstrated at a hacking contest.

Malware & Threats

Google ships a security-themed Chrome browser refresh to fix flaws exploited at the CanSecWest Pwn2Own hacking contest.

Vulnerabilities

Firefox browser updates address two zero-day vulnerabilities exploited at the Pwn2Own hacking contest.

Vulnerabilities

Exploits targeting Tesla cars, operating systems, and popular software earned participants over $1.1 million at Pwn2Own Vancouver 2024.

IoT Security

Participants earned a total of $732,500 on the first day of Pwn2Own Vancouver 2024 for hacking a Tesla, operating systems, and other software.

IoT Security

Participants have earned more than $1.3 million for hacking Teslas, EV chargers and infotainment systems at Pwn2Own Automotive.

IoT Security

Over $1 million paid out in the first two days of Pwn2Own Automotive for Tesla, infotainment and EV charger hacks.

IoT Security

On the first day of Pwn2Own Automotive participants earned over $700,000 for hacking Tesla, EV chargers and infotainment systems.

Copyright © 2024 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version