HomeCyber SecurityA Security Researcher Has Discovered That The Creative Katana V2X USB Soundbar...

A Security Researcher Has Discovered That The Creative Katana V2X USB Soundbar Can Be Used To Hijack A Connected Windows PC Over Bluetooth With No Pairing, No Authentication, And From Up To 15 Metres Away

Researcher Rasmus Moorats Found That The Speaker’s Internal Control Protocol Is Exposed Over Bluetooth LE Without Any Security, Allowing Malicious Firmware To Be Pushed Wirelessly, Turning The Speaker Into A BadUSB Keyboard That Silently Types Commands On Your PC

According to TechTimes and Ars Technica, security researcher Rasmus Moorats has discovered a critical vulnerability in the Creative Katana V2X, a popular USB-connected soundbar, that allows nearby attackers to install malicious firmware over Bluetooth Low Energy and then use the compromised speaker as a BadUSB device to execute arbitrary commands on a connected Windows PC.

Moorats found that the speaker’s internal Control Transfer Protocol; CTP, is exposed over BLE without any pairing or authentication requirement. While CTP is intended for firmware updates and settings changes via an authenticated USB connection, the same commands are accessible wirelessly to any device within approximately 15 metres.

The only firmware protection in place is a SHA-256 checksum with no cryptographic signature, meaning an attacker can modify firmware, recompute the checksum, and push the altered image entirely over Bluetooth. Moorats demonstrated this by replacing the speaker’s “WELCOME” startup string with “PATCHED,” and then showed how a hacked speaker could silently execute keyboard commands on a connected Windows machine.

Because the device also includes a microphone, a malicious firmware image could convert it into a covert listening device controlled remotely over BLE.

Creative told Moorats the report “does not indicate a cybersecurity risk.” No vendor patch has been released. Moorats published his own interim firmware fix blocking CTP over Bluetooth.

To check out our previous coverage on cybersecurity, hardware vulnerabilities, and Bluetooth security, read our articles here.

RELATED ARTICLES

Most Popular