EC-Council Certified Ethical Hacker (CEH) v12Mobile Platform, IoT, and OT HackingEasy

A cybersecurity analyst is investigating an incident where a smart thermostat in a manufacturing plant was remotely manipulated, causing a critical temperature fluctuation that disrupted production. The thermostat communicates wirelessly within a segmented network. Which of the following attack vectors was most likely exploited in this scenario?

  1. ADefault/Weak Credentials
  2. BDenial of Service (DoS)
  3. CCross-Site Scripting (XSS)
  4. DSQL Injection
Show answer & explanation

Correct answer: A. Default/Weak Credentials

IoT devices are frequently deployed with default passwords or easily guessable credentials, making them prime targets for unauthorized access and control. Remotely manipulating a device typically involves authentication, which weak credentials compromise.

Why the other options are wrong

  • B. Denial of Service (DoS) aims to make a service unavailable, not to manipulate its functions like temperature control.
  • C. Cross-Site Scripting (XSS) targets web applications to inject malicious scripts, not direct device control.
  • D. SQL Injection targets databases, not typically used for direct device manipulation in a thermostat.

IoT Default Credentials

Pre-set usernames and passwords on Internet of Things (IoT) devices that are often not changed by users, creating a significant security vulnerability.

  • Many IoT devices ship with universal default credentials.
  • Attackers can easily find lists of these defaults online.
  • Failure to change them allows unauthorized remote access.

Memory trick: IoT's door is often open with default keys.

More Mobile Platform, IoT, and OT Hacking questions