Hackers can use smart plugs to break into your home network

Cybersecurity
(Image credit: Shutterstock / song_about_summer)

Cheap smart plugs are a major cybersecurity vulnerability and could easily be used by criminals to break into a person’s devices, or even home, experts are saying. 

In a blog post, security firm A&O IT Group detailed its security analysis of two cheap and widely available smart plugs - the Sonoff S26 and the Ener-J WiFi.

These smart plugs, which can reportedly easily be obtained on Amazon, eBay and Aliexpress for as little as $10, can be used to obtain login credentials to the target’s WiFi network. This was made possible due to the fact that these devices communicate with the router via port 80, sending unencrypted HTTP traffic, as well as due to weak factory passwords.

Once the attackers obtain WiFi credentials, they’re able to connect to the target network and from there do all kinds of nasties, from receiving video and audio from laptops, controlling vulnerable smart devices, downloading sensitive data or even monitoring traffic from other devices. 

They could also use the WiFi to download illegal material from the internet, or launch attacks on other users’ devices, with virtually no chance of being caught.

Setting up a guest SSID

This becomes even more concerning if the victim has things like smart door locks or video surveillance on the same network. In that scenario, an attacker would even know when the residents are out and about, and could even be able to break into the premises. 

A&O IT Group says it has notified both Sonoff and Ener-J of the discovered vulnerabilities but is yet to hear back from either manufacturer. 

To mitigate the issue, experts from CNX Software, are saying, the quickest way is to set up a guest SSID for the IoT gadgets, so that other important devices don’t share the same network.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A hacker wearing a hoodie sitting at a computer, his face hidden.
I just learned something awful about my home Wi-Fi setup thanks to iFixit’s ‘worst of CES 2025’ awards
Woman setting up air fryer using phone
Your air fryer might be sharing your private data – here's how you can protect yourself now
China
Chinese hackers develop effective new hacking technique to go after business networks
Abstract image of cyber security in action.
TikTok’s American ownership rule ignores bigger IoT threat
Bluetooth
Top Bluetooth chip security flaw could put a billion devices at risk worldwide
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
IoT’s botnet problem is up 500% – three things admins must do now
Latest in Security
An American flag flying outside the US Capitol building against a blue sky
The FCC is creating a security council to bolster US defenses against cyberattacks
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Ransomware
Microsoft uncovers sleuthy new XCSSET MacOS malware campaign
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Meta warns of worrying security flaw hitting open source type software
Hand holding smartphone and scan fingerprint biometric identity for unlock her mobile phone
Biometrics add another layer of security to passwordless authentication
Data leak
Hacked Tata Technologies data leaked by ransomware gang
Latest in News
Google Gemini Flash 2.0 Images
I tried Gemini's new AI image generation tool - here are 5 ways to get the best art from Google's Flash 2.0
An image of the Samsung Galaxy S25 Ultra from a hands-on event
Samsung Galaxy S26 Ultra could resurrect an intriguing camera feature
Eurocom Raptor X18
At $15,000, this massive 256GB RAM laptop makes Apple's MacBook Pro look affordable, tiny and very, very slow
Cristin Milioti in Black Mirror season 7
Netflix launches trailer for Black Mirror season 7, giving us a look at its first-ever sequel episode and an unexpected returning character
A graphic of the PC Gaming Show
Get ready for a bounty of PC games on June 8, as the PC Gaming show is back
A close up of The Daily podcast from Pocket Casts' web page
‘Podcasting shouldn’t be locked behind walled gardens’: Pocket Casts slams Spotify and makes its web player free to all