Getting the Firmware
The first step is always to get the firmware. Researchers download it from official websites, capture it during OTA updates, or dump it from the device via serial ports. Some vendors skip certificate verification in OTA updates. A man-in-the-middle attack works for years. If a device has remote code execution, they use BusyBox or Netcat to pull the firmware. Many devices store a local copy for recovery. Command injection bugs still exist. A simple semicolon is enough to get RCE.
Hidden Backdoors Built by Manufacturers
Not all backdoors come from hackers. Many are built in by the manufacturer. Hardcoded super admin passwords stay secret but are reversible from the firmware. One hidden account was named after the vendor’s headquarters location. Another encryption key was a slogan from a Taiwanese forum board. Debug ports like Telnet are left open. Even if closed, a hidden CGI script or API path can re-enable it. MQTT credentials are hardcoded in the device, often in plain text. Researchers subscribe to topics and access devices worldwide.
The Bureaucracy of Reporting Bugs
Reporting bugs is the real challenge. In September 2024, a critical RCE bug was reported in a device used on Taiwan government networks. The vendor replied: “This device is end of life, so we won’t fix it.” 60,000 units of that model are still online. A few months later, a second model with the same firmware and bug was found. The vendor only listed the first model. Researchers had to file a new CVE for the twin. Another vendor ignored a bug for three years. Silence meant no patch, no advisory. Some vendors demand a broad NDA: “Find bug but don’t tell anyone.”
What Vendors, Governments, and Users Can Do
Manufacturers must stop leaving secret backdoors and hardcoded passwords. Debug ports are not the problem. Hidden ports are. Vendors should document all access points and respond quickly to bug reports. Governments should enforce rules against hidden backdoors and slow patches. Users should buy from companies that care about security, update firmware, and report strange behavior. Researchers should find backdoors, report them responsibly, and put user safety first. Working together makes IoT safer.
Notable Quotes
Most People think IoT security is about stopping hacker. But what if the back door is already open? Kai-Ching “Keniver” Wang · ▶ 1:24
No hacking is needed. Just plug in the device and you can get inside. Chiao-Lin “Steven Meow” Yu · ▶ 1:36
Sometimes simple semicolon is all you needed. Kai-Ching “Keniver” Wang · ▶ 6:41
This device is end of life, so we won’t fix it. Vendor response · ▶ 13:16
Security issue don’t age like wine they don’t get better with age. Chiao-Lin “Steven Meow” Yu · ▶ 16:26
Key Takeaways
- Hidden backdoors from manufacturers are common and often ignored.
- Reporting bugs can take months or years with no fix from vendors.
- 60,000 vulnerable end-of-life devices remain online after disclosure.
About the Speaker(s)
Kai-Ching “Keniver” Wang is a Senior Security Researcher at CHT Security. He specializes in red team assessments and comprehensive security reviews, with a current focus on hacking IoT devices and cloud-native infrastructure. He has presented his research on the security of cloud-connected IoT camera systems at conferences such as SECCON in Japan and HITCON in Taiwan.
Chiao-Lin “Steven Meow” Yu currently serves as a Senior Red Team Cyber Threat Researcher at Trend Micro Taiwan. He holds numerous professional certifications including OSCE³, OSEP, OSWE, OSED, OSCP, CRTP, CARTP, CESP-ADCS, LPT, CPENT, GCP ACE. Steven has previously presented at events such as HITCON Training 2025, Security BSides Tokyo 2023, and CYBERSEC 2024, 2025. He has disclosed 30+ CVE vulnerabilities in major companies like VMware, D-Link, and Zyxel. His expertise spans Red Team exercises, Web security, IoT security and Meow Meow security.