This top home security system could be disabled remotely

Best Business Security System
(Image credit: Andrey Popov / Shutterstock)

A popular home security system can reportedly be disabled, according to cybersecurity researchers.

Researchers at Rapid7 found a pair of vulnerabilities in the Fortress S03 home security system that relies on Wi-Fi to connect cameras, motion sensors and sirens to the internet, to enable owners to remotely monitor their home. 

Rapid7 has shared the details about the two vulnerabilities after it did not hear from Fortress in over three months, which is the standard window of time for security disclosures, followed by the industry. 

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

According to the timeline shared by Rapid7, it is confident it got through to the company since Fortress silently closed its first support ticket over a week later after it was created.

Anybody home?

As per the details shared by Rapid7, it found that the Fortress S03 system relies on a radio-controlled key fob that helps arm and disarm the system. 

Its researchers discovered that signals from the keys were unencrypted and could be intercepted, which enabled them to capture and replay the signals for “arm” and “disarm”.

It found a second vulnerability in Fortress’ unauthenticated API, which can be remotely queried over the internet without the server checking the legitimacy of the request. All it takes is a homeowner’s email address for the server to return the device’s unique IMEI code, which can be used to remotely disarm the system.

Rapid7 claims it brought the issues to Fortress’ knowledge, but the company never returned their messages, even after it raised a new ticket reiterating their intent to publish the details.

While Fortress did not respond to queries from TechCrunch, an email from their law firm labelled Rapid7’s claims as “false, purposely misleading and defamatory,” without adding more details. 

Via TechCrunch

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
Thousands of misconfigured building access systems have been leaked online
Best free Linux firewalls
Fortinet warns a critical vulnerability in its systems could let attackers breach company networks
Ransomware
Fortinet firewall bugs are being targeted by LockBit ransomware hackers
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
Best free Linux firewalls
Palo Alto firewalls have some worrying serious flaws
Man and woman setting up home security camera
How to secure your home with smart tech
Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does