Osram Fixes Flaws in Lightify Connected Light Bulbs

Published: Jul 26, 2016
Updated: Feb 2, 2021
3 minute read
IoT security
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Among the popular emerging use cases for the internet of things is connected lightbulbs that users can control remotely. New research disclosed July 26 by security vendor Rapid7 reveals that it discovered numerous flaws in the Osram Lightify product lineup, which could have exposed users to risk. The company fixed most of the flaws in a patch update.

Rapid7 found nine issues affecting the Home and Pro version of the Osram Lightify products. Among the vulnerabilities is CVE-2016-5051, a network WiFi password vulnerability. Rapid7 found that the mobile application for Lightify Home saved the user’s WiFi password as clear text.

“Based on my personal experience of testing mobile applications over a number of years, it is very common to see this type of vulnerability—where mobile applications are storing passwords, in clear text,” Deral Heiland, research lead at Rapid7, told eWEEK.

Another flaw Rapid7 identified is CVE-2016-5053, which enables users on the local network to get access without a password. Rapid7 often finds home automation technology deployed in small businesses or offices, and if these internet of things (IoT) technologies are deployed on networks, there is a shared risk of abuse and compromise becomes more critical, Heiland said.

“The ability to reconfigure a device over the network without any form of authentication is a security design flaw that needs to be avoided,” he said.

The way the Osram Lightify connected bulbs communicate is over the ZigBee wireless protocol. One of the vulnerabilities Rapid7 discovered is a ZigBee network command replay attack (CVE-2016-5054). According to Rapid7’s advisory, it is possible for a malicious actor to capture and replay the Zigbee communication at any time, and replay those commands to disrupt lighting services without any other form of authentication.

Monitoring, capturing and replaying ZigBee communication is easily done using a RZUSBSTICK and Killerbee project code, Heiland explained.

Osram Lightify bulbs can also work on non-Lightify hubs and with third-party mobile apps. For example, it’s possible to run Lightify bulbs on a Belkin WeMo link, with the WeMo mobile app. For Lightify bulbs running on non-Lightify hubs and apps, users could still be at risk potentially from flaws in ZigBee, which could allow commands to turn lights on and off, to be vulnerable to a replay attack, Heiland said.

Advertisement

“From the perspective of a home user, the risk is very low, and attackers would most likely leverage the vulnerability as form of harassment,” Heiland said.

To find the flaws in the Osram Lightify products, Rapid7 assessed the embedded device, mobile applications, cloud API, network communications (Ethernet, WiFi, ZigBee), firmware and code, where possible. To analyze Osram Lightify, the products were installed and tested in a full functioning environment so the complete ecosystem could be analyzed.

Osram has patched most of the security flaws that Rapid7 found.

Heiland commented that Osram’s response to Rapid7’s finding was very positive. “I worked closely with Osram during the testing of the Lightify Pro version, and they were very helpful and cooperative during the whole process,” Heiland said. “Without their help, it would have been difficult to conduct a thorough evaluation of the Lightify Pro devices security.”

Overall, Heiland emphasized that his goal in disclosing the issues with Osram Lightify is to build further awareness for manufacturers of IoT devices, and to help educate consumers of these devices.

“My hope is that future and current vendors will improve their security features, and we can avoid these types of attacks becoming a real issue for the home owners and businesses that utilize these solutions,” Heiland said.

Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

Sean Michael Kerner

Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。