Skip to content

Instantly share code, notes, and snippets.

View Arduous's full-sized avatar

Samuel Progin Arduous

View GitHub Profile
@Julius2342
Julius2342 / velux.md
Last active August 6, 2021 15:44
Velux security flaw within KLF 200

Security Flaw within VELUX KLF 200

Another episode of Internet Of Things done wrong. This exploit is so trivial, i would not even call it exploit.

Introduction

VELUX[0] is the leading manufacturer of roof windows (They are really great!). VELUX KLF 200 is a device to control VELUX windows over ethernet/internet[1]. The KLF 200 device has an undocumented API for executing scenes, with other words opening and closing velux windows.