The latest build was years old, so that wasn't too hard. I found an outdated service that is reachable unauthenticated from LAN and has a known vulnerability that allows arbitrary file reads on the device. I also found another endpoint that is unauthenticated from LAN and with a single GET request essentially bricks the device, requiring disassembly and JTAG access to recover from. There are no cross-origin checks or restrictions of any kind, so a malicious site could put the URL in an img tag or similar and brick visitors' devices with no interaction.
I'm in the EU, so I went to their EU site where I was first instructed to create a ticket on their support site. I tried numerous times but it always failed with "an unknown error", instructing me to "contact the service desk" with no clues how to reach them. I also found another form where you could select security issue as the topic, but the description field was barely long enough to fit "I found security issues with ${product}, please contact me for more details." Three weeks later I'm still waiting.
Next I filed the same security issue form on their US site, and promptly got a reply. The exact model isn't sold in the US so they wouldn't handle it directly, but promised to forward any details to their EU counterpart since I had such a hard time reaching them directly. I sent the issue details and have not heard back since. I sent a follow-up email asking for a status update, but so far that has gone unanswered too.
What should I do next? Is there some EU entity that could step in? Can I get in trouble if I just publish what I found?
stop50•6h ago
cudder•3h ago