T09 · Insecure Skill Coding Practices
- Location
st200th_mqtt.py:38- Finding
Shared Credentials and Plaintext MQTT Allow Unauthorized Device Control
- Content
View full analysis
/publish /public//subscribe ``` No command signature, per-device secret, nonce validation, or application-level authorization is implemented. The exposed command interface includes configuration changes, reboot, factory reset, and OTA upgrade. ### Attack Path 1. The attacker downloads or inspects the skill package and obtains the embedded ...[truncated 1426 chars]- Remediation
View remediation
