Header banner
Revain logoHome Page
Obhed Mac photo
United Kingdom, Belfast
1 Level
729 Review
34 Karma

Review on Sengled Z02 Hub Smart Hub White by Obhed Mac

Revainrating 3 out of 5

Vulnerability in Hub/Open Web Server

I recently bought your Sengled Element lightbulbs with a hub. After setting up the Sengled Hub on my test network, I scanned the hub's IP address for open ports. Surprisingly, port 80 was wide open. Port 80 usually means there is a web server behind it. I tried to access the website hosted on this port and it was the Realtek WLAN Access Point web server management console page. I went through all the settings and found that no admin userid or password was set. I set an admin userid and password to make the web server a little more secure. This must be ensured. Your customers have no idea that they are running a wide-open web server that is vulnerable to hackers. By accessing various pages on the web server, it looks like I can get the password for the main wi-fi that the hub was connected to, which was in clear text. The hackers could also change the access point's mode, making it a rogue router on the network. They can also result in the hub not connecting to lightbulbs at all, which is also bad for physical security. The hub should be set to internal WiFi instead of something like guest WiFi.

Pros
  • Nice to use
Cons
  • Not bad