
I recently bought your Sengled Element lightbulbs with a hub. After setting up the Sengled Hub on my test network, I scanned the hub's IP address for open ports. Surprisingly, port 80 was wide open. Port 80 usually means there is a web server behind it. I tried to access the website hosted on this port and it was the Realtek WLAN Access Point web server management console page. I went through all the settings and found that no admin userid or password was set. I set an admin userid and password to make the web server a little more secure. This must be ensured. Your customers have no idea that they are running a wide-open web server that is vulnerable to hackers. By accessing various pages on the web server, it looks like I can get the password for the main wi-fi that the hub was connected to, which was in clear text. The hackers could also change the access point's mode, making it a rogue router on the network. They can also result in the hub not connecting to lightbulbs at all, which is also bad for physical security. The hub should be set to internal WiFi instead of something like guest WiFi.

Remotec ZRC-90US & BW8510US | Cert ID ZC10-15100007
9 Review

🏠 Aeotec Smart Home Hub: The Ultimate SmartThings Hub and Z-Wave Zigbee Gateway with Alexa, Google Assistant, and WiFi Compatibility
9 Review

SONOFF SNZB-03 ZigBee Motion Sensor: Wireless 🔦 Alerts and Light Trigger with SONOFF Zigbee Bridge
9 Review

🏠 Aqara Cube - Zigbee Connection, Smart Home Device Controller with 6 Customizable Gestures, 2-Year Battery Life - Works with AQARA HUB and IFTTT
16 Review

💡 Hydrofarm Quantum QT400 Dimmable Ballast for 400W Grow Lights
5 Review

💡 High-Quality Advance ICN-4P32-SC Electronic Fluorescent Ballast: Ideal for 4 Lamps, 32W T8, 120/277V
3 Review

Fulham WorkHorse WH2-120-C Adaptable Ballast - 2 Pack
3 Review

🔌 Robertson 2P20132 Quik-Pak: 10 Fluorescent eBallasts for 2 F40T12 Linear Lamps, Preheat Rapid Start, 120Vac, 50-60Hz, Normal Ballast Factor, NPF, Model RSW234T12120 /A (Crosses to RSW240T12120 /B)
4 Review