The SDK Problem

▶ Watch (0:03)

SDKs are collections of drivers, toolchains, and example code that chip makers provide to device makers. Chipsets change ownership frequently, leaving new owners to inherit SDKs they didn’t develop. Device makers often ship example code meant only for development. Outdated libraries and forked projects never updated compound the problem. Lawshae found a UDP service in the Oculus that the vendor didn’t know existed. It belonged to the chipset SDK. One command injection bug can exploit every device running that chip.

Attack Surfaces of Common Chipsets

▶ Watch (7:55)

Broadcom’s IoT chipsets use a mashup of microHTTP, miniHTTP, and Go-Ahead for their web servers. Their UPnP implementation is buggy and appears to be ripped from Rawlink’s version. The WICED SDK, now owned by Cypress after a series of acquisitions (Avago bought Infineon in 2008, later Broadcom, then Cypress bought the IoT portfolio in 2016), carries these same services. Source code for some SDKs is available online, aiding research. Lawshae notes that similar proprietary services get copy-pasted across SDK versions.

Command Injection and Immortal Bugs

▶ Watch (11:04)

Lawshae loves command injection bugs because they are architecture-independent. One such bug can compromise every device using that chipset. He found a command injection in Realtek’s UPnP implementation in 2014. That same vulnerability landed on CISA’s KEV list ten years later, still actively exploited. Quantenna chipsets, used in AT&T set-top boxes, expose a QCS API with hundreds of remote commands. Despite acquisitions (Quantenna bought by ON Semiconductor), these services persist in devices.

Notable Quotes

I love command injection bugs. They’re my favorite type of bug Richard “HeadlessZeke” Lawshae · ▶ 07:07

chipsets end up changing ownership quite a bit Richard “HeadlessZeke” Lawshae · ▶ 03:04

once a vulnerability is found like you can’t put the genie back in the tube of toothpaste Richard “HeadlessZeke” Lawshae · ▶ 05:57

Key Takeaways

  • SDK bugs persist through acquisitions and product lines, rarely patched.
  • Command injection bugs are architecture-independent, enabling wide exploitation.
  • A Realtek bug from 2014 remains on CISA KEV list, showing decade-long risk.

About the Speaker(s)

Richard “HeadlessZeke” Lawshae is a Principal Security Researcher for Keysight Technologies. He has been hunting vulnerabilities in IoT devices for the past 15 years or so and has discovered and disclosed dozen of vulnerabilities in products from HID Global, Crestron, Meta, Mazda, Realtek, and more. His work has been featured in Wired, Forbes, Hackaday, and the CISA KEV list. He is based out of beautiful Austin, TX (AHA! represent).