Gaming soundbar could be hijacked from over 16 yards away with out contact or pairing — the corporate allegedly refuses to label the blatant safety flaw a cybersecurity threat

This web page was created programmatically, to learn the article in its authentic location you may go to the hyperlink bellow:
https://www.tomshardware.com/tech-industry/cyber-security/creatives-sound-blaster-katana-v2x-can-be-hijacked-over-bluetooth
and if you wish to take away this text from our web site please contact us


Security researcher Rasmus Moorats has demonstrated that Creative’s Sound Blaster Katana V2X gaming soundbar could be hijacked over Bluetooth from roughly 16 yards (15 meters) away, with no pairing or bodily contact, in a blog post printed on June 3. By exploiting an unauthenticated Bluetooth interface and the absence of firmware signing, an attacker can flash customized firmware onto the speaker over the air, turning the USB-connected system right into a keyboard that varieties instructions into the host PC. Creative, which was contacted by way of Singapore’s nationwide cyber response group, took shut to 2 months to answer and concluded the conduct was not a safety threat, leaving house owners of the ~$280 soundbar with out an official patch.

The Katana V2X communicates with Creative’s desktop app through a proprietary protocol that Moorats refers to because the Creative Transfer Protocol (CTP). Over USB, the speaker requires a challenge-response handshake earlier than accepting any command, however over Bluetooth Low Energy, the identical protocol accepts the identical instructions with out authentication or pairing, so any system in vary might learn settings, change them, or push firmware. The firmware itself carries no cryptographic signature, solely a SHA-256 checksum that Moorats recomputed after modifying the picture.


This web page was created programmatically, to learn the article in its authentic location you may go to the hyperlink bellow:
https://www.tomshardware.com/tech-industry/cyber-security/creatives-sound-blaster-katana-v2x-can-be-hijacked-over-bluetooth
and if you wish to take away this text from our web site please contact us