Table of Contents
This guide provides a clear, practical overview of this critical vulnerability turns home devices into attack, with useful context, important details, and straightforward takeaways for everyday readers.
Cybersecurity firm Mandiant, the Cybersecurity and Infrastructure Agency (CISA) and ThroughTek said the vulnerability appeared in IoT devices using the ThroughTek Kalay platform.
This vulnerability (codenamed CVE-2021-28372) has a CVSS of 9.6, which is classified as a critical vulnerability. Experts recommend that users upgrade to Kalay version 3.1.10 to protect devices and networks from attackers.
While Mandiant cannot aggregate all affected devices, ThroughTek figures show 83 million devices are connected through the Kalay network and there are more than 1.1 billion monthly connections to the platform.

Previously, Nozomi Networks also found security holes in ThroughTek, but the new vulnerability discovered by Mandiant is different. It allows attackers to remotely execute code on the device, take control of affected IoT devices, listen to live audio, view real-time video feeds, and compromise device credentials. to prepare for the next attack.
This is a privacy violation that seriously affects not only individual customers, especially if cameras and surveillance equipment are installed inside a private home, but also for businesses as it can monitor live. internal and private meetings.
In addition, there is also the possibility of devices being used in botnets and DDoS attacks.
"This vulnerability could potentially allow remote code execution on the attacked device, which could be used in a variety of ways, such as potentially creating a botnet from vulnerable devices or being hacked. attacks on devices that share the same network as the attacked device," said Erik Barzdukas, service manager at Mandiant.
Exploiting the CVE-2021-28372 vulnerability is very complex, requiring the attacker's time and effort. However, this did not prevent breaches from occurring, and the vulnerability is still considered critical by CISA.
Mandiant is working with vendors using the Kalay protocol to help protect devices from vulnerabilities and recommends that all IoT manufacturers and users update patches to protect devices. .
Key Takeaways
Use the information above as a practical reference for this critical vulnerability turns home devices into attack. Review each step carefully, confirm any requirements, and choose the option that best fits your situation.
FAQ
What does this guide explain about This Critical Vulnerability Turns Home Devices into Attack?
It explains the main concepts, practical considerations, and useful steps related to this critical vulnerability turns home devices into attack without requiring advanced knowledge.
Who can benefit from learning about This Critical Vulnerability Turns Home Devices into Attack?
This information is useful for readers who want a clear overview, practical guidance, and reliable steps related to this critical vulnerability turns home devices into attack.
What should I check before applying this information?
Review the requirements, confirm that your device, software, or situation matches the instructions, and back up important data before making major changes.
Reader Comments 0
Sign in with email or Google to join the discussion.