If you are from India, you may have seen the e-rickshaw battery videos this week on how e-rickshaws are getting so called “hacked” & disabled and India govt banning the vendor apps allowing for Battery Management System access.
TBH its not even a hack. Its a safety feature to probably remote turn off BMS in case some over heating. Most vendors selling them in India didn’t put a firmware lock on those. When you white label and import without knowing anything about the product, this is bound happen.

This issue reminded me of a Bluetooth security case last year. At a security conference, ERNW researchers showed vulnerabilities in Airoha-based Bluetooth audio devices. These chips are used in many headphones and earbuds(even the high end ones like Sony).
A headphone is trusted by your phone because both devices store a cryptographic bond. In Bluetooth Classic, one part of that trust is the link key. Once your phone pairs with the headphone, it accepts that device again because the key matches.
The researchers found a vendor protocol exposed over Bluetooth. On affected devices, a nearby attacker could use that protocol without proper authentication. It could read flash, read or write RAM, and extract Bluetooth link keys. This affected most devices with Airoha chips. All an attacker needs is to be in the range within the device. Thats it.
Attacker can impersonate the headphone to the phone. From the phone’s PoV, the old trusted headset has returned. Once a device is accepted as a headset, it can route audio, touch call controls, interact with the microphone path, record audio, and trigger voice assistants. Since its an year old, I think the vulnerability is fixed.
If you build Bluetooth products, for the love of God, please keep the vendor SDK current. Pull the latest vendor firmware, enforce pairing and authentication on every GATT and RFCOMM path, remove unused services, restrict connection parameters, and test what a nearby untrusted phone can actually do. Please remember any maintenance interface exposed over Bluetooth is a public attack surface.
0 Comments