Dangerous backdoor exploit found on popular IoT devices

In yet another worrying piece of Internet of Things security news, a backdoor has been found in devices made by a Chinese tech firm which specialises in VoIP products.

Security outfit Trustwave made the discovery of a hidden backdoor in DblTek’s devices which was apparently put there to allow the manufacturer access to said hardware – but of course, it’s also open to being exploited by other malicious parties.

The backdoor is in the Telnet admin interface of DblTek-branded devices, and potentially allows an attacker to remotely open a shell with root privileges on the target device.

What’s perhaps even more worrying is that when Trustwave contacted DblTek regarding the backdoor last autumn – multiple times – patched firmware was eventually released at the end of December.

However, rather than removing the flaw, the vendor simply made it more difficult to access and exploit. And further correspondence with the Chinese company has apparently fallen on deaf ears.

Other brands

Trustwave notes that the firmware with the hole in it is present on almost every GSM-to-VoIP device which DblTek makes (hardware which is mainly used by SMBs). Trustwave has apparently found hundreds of these devices on the net, and many other brands which use the same firmware, so are equally open to exploit.

The security company also said that it has been able to successfully exploit both the old backdoor, and the new (better hidden) modified version which was patched in at the end of last year.

It’s no surprise that concerns are mounting about IoT security, particularly when you look at a case like this. It’s not just about the pure amount of potential vulnerabilities on connected devices out there, but also purposeful backdoors, and inadequate responses when clearly dangerous issues are pointed out.

Darren is a freelancer writing news and features for TechRadar (and occasionally T3) across a broad range of computing topics including CPUs, GPUs, various other hardware, VPNs, antivirus and more. He has written about tech for the best part of three decades, and writes books in his spare time (his debut novel - 'I Know What You Did Last Supper' - was published by Hachette UK in 2013).

Latest in Pro
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
Context Windows
Why are AI context windows important?
BERT
What is BERT, and why should we care?
A person holding out their hand with a digital AI symbol.
AI is booming — but are businesses seeing real impact?
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
Latest in News
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does