This nasty security vulnerability could turn millions of smart devices into spying tools

security
(Image credit: Shutterstock / rudall30)

A security vulnerability has been identified in software deployed across millions of internet-connected devices with audio and video functionality.

According to researchers at Nozomi Networks, the flaw could allow attackers to effectively turn smart devices - such as baby monitors, home security cameras or smart doorbells - into spying tools.

In a business context, meanwhile, the security flaw could be exploited to gain access to sensitive employee and customer data, or gather intel on production techniques.

The bug has been awarded a severity rating of 9.1/10 as per the Common Vulnerability Scoring System (CVSS), due to the wide scope and low complexity of the exploit.

IoT security vulnerability

The offending software component, known as P2P, is developed by a company called ThroughTek. In legitimate scenarios, the P2P SDK is used by manufacturers to build remote access functionality into IoT devices.

The vulnerability is said to affect P2P SDK versions 3.1.5 and prior, as well as any versions with the nossl tag. ThroughTek remedied the issue with version 3.3, rolled out in mid-2020, but a significant proportion of devices are thought to be running out-of-date builds.

A proof-of-concept developed by Nozomi demonstrates that older versions of the P2P SDK allow for data packets to be intercepted in transit and then decrypted. These packets can then be reconstructed into complete audio or video streams.

In a blog post, ThroughTek suggests an attacker would require a deep knowledge of network security, network sniffer tools and the encryption algorithm in order to execute the attack. And the researchers also conceded that it would be difficult for an attacker to identify which IoT devices are vulnerable and which not.

Nonetheless, manufacturers that utilize the P2P SDK are advised to upgrade to the latest version immediately to shield against attack.

“The most chilling reminder with this research is that despite all the technical advances in connected devices, and our reliance on them during the past year’s lockdown, IoT is still racked with insecurity,” said Nozomi.

Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Read more
Bluetooth
Top Bluetooth chip security flaw could put a billion devices at risk worldwide
botnet
Another top security camera maker is seeing devices hijacked into botnet
A VPN runs on a mobile phone placed on a laptop keyboard
Major new online tunneling vulnerability could put millions of devices at risk
An image of network security icons for a network encircling a digital blue earth.
Industrial networks exposed to attack by faulty Moxa devices
A VPN runs on a mobile phone placed on a laptop keyboard
SonicWall firewalls hit by worrying cyberattack
vpn
Ivanti warns another critical security flaw is being attacked
Latest in Security
Data leak
Top home hardware firm data leak could see millions of customers affected
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Android Logo
Devious new Android malware uses a Microsoft tool to avoid being spotted
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Latest in News
A business woman looking at AI on a transparent screen
Most businesses are now fully embracing AI - but aren't always protected against the risks
Cristiano Ronaldo promotional image for Fatal Fury: City of the Wolves
Yes, Cristiano Ronaldo is a playable character in Fatal Fury: City of the Wolves, and it makes more sense than you think
Buzz Lightyear Space Ranger Spin Rennovations
Disney’s giving a classic Buzz Lightyear ride a tech overhaul – here's everything you need to know
Hisense U8 series TV on wall in living room
Hisense announces 2025 mini-LED TV lineup, with screen sizes up to 100 inches – and a surprising smart TV switch
Nintendo Music teaser art
Nintendo Music expands its library with songs from Kirby and the Forgotten Land and Tetris
Opera AI Tabs
Opera's new AI feature brings order to your browser tab chaos