Hackers can remotely control Aga cookers with an SMS

IoT exploit of upmarket oven control could ruin your quinoa risotto

Hackers could remotely control the latest IoT-equipped Aga ovens by just sending a text message, according to security researchers.

The latest Aga ovens feature an IoT device called Total Control, which allows users to access the oven's functions through a mobile or web app. The device connects to the internet via a SIM card and a cellular radio connected to a mobile phone network. This enables Aga ovens to receive and send text messages from anywhere in the world. 

But according to Ken Munro, partner at Pen Test Partners, hackers can quite easily operate the cooker without the owner's knowledge.

In a blog post, he said the mobile app passes messages onto an API, but the app communicates over plain text HTTP. He added that the Android app explicitly disables certificate validation through use of ALLOW_ALL_HOSTNAME_VERIFIER. "Even if it did offer SSL, it would thus be trivial for rogues to intercept and modify traffic," he said. 

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

He found that the physical module connected to the oven contained a GSM SIM, which costs 6 per month to maintain mobile connectivity.

But the main issue was the web app that allowed plain text over HTTP, which said Munro, didn't protect customer data in transit. The app enumerates the SIM card phone number, mistype a number and an error will appear.

"Put in a valid number (i.e. +44 845 712 52 as suggested by the app when you make an invalid entry) and you'll see that it's already registered. It's not actually a valid phone number, so likely someone has been interfering with this website!" he said.

"So those with nefarious intentions could enumerate a list of all the valid Aga cooker phone numbers. Time consuming, but likely effective."

He added that the app's password policy is only five characters. "This is starting to get pretty irresponsible of Aga; customers will have their cookers compromised," said Munro.

Munro said the app also had no validation of the number and authentication of messages, meaning that hackers could simply send a text to a cooker and turn them off or on at will.

Advertisement - Article continues below

"One could also power up people's Agas when they're not looking, wasting electricity. They draw around 30 Amps in full heat-up mode, so if you could switch enough Agas on at once, one could cause power spikes," said Munro.

He added that the web interface lends itself to "spamming the hell out of people using SMS at Aga's expense".

Munro said that the disclosure process with Aga was a "train wreck".

"We tried Twitter, every email address we could find and then rang them up. No response to any of the messages we left."

Advertisement
Advertisement - Article continues below

He urged the firm to ditch the SMS based remote control module and put in a secure Wi-Fi enabled module with mobile app.

He also noted that the SIM module is made by Tekelek and this company has a history in remote monitoring of oil storage tanks, heating systems, process control and medical devices among many things. 

Advertisement - Article continues below

"These appear to be monitored using SMS, so I wonder where else this bizarre unauthenticated text messaging process might lead," said Munro.

IT Pro has approached Aga for comment.

Featured Resources

Report: The State of Software Security

This annual report explores important trends in software security

Download now

A fast guide to finding your cloud solution

One size doesn't fit all in the cloud, so how do you find the best option for your business?

Download now

Digitally perfecting the supply chain

How new technologies are being leveraged to transform the manufacturing supply chain

Download now

Small & Medium Business Trends Report

Insights from 2,000+ business owners and leaders worldwide

Download now
Advertisement

Recommended

Visit/security/internet-security/354417/avast-and-avg-extensions-pulled-from-chrome
internet security

Avast and AVG extensions pulled from Chrome

19 Dec 2019
Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

Visit/mobile/28299/how-to-use-chromecast-without-wi-fi
Mobile

How to use Chromecast without Wi-Fi

5 Feb 2020
Visit/hardware/354723/coronavirus-starts-to-take-its-toll-on-the-tech-industry
Hardware

Coronavirus starts to take its toll on the tech industry

6 Feb 2020
Visit/operating-systems/microsoft-windows/354739/windows-7-bug-blocks-users-from-shutting-down-their-pcs
Microsoft Windows

Windows 7 bug blocks users from shutting down their PCs

10 Feb 2020
Visit/in-depth/354726/sonos-speakers-are-environmentally-unsound
In-depth

Sonos speakers are environmentally unsound

9 Feb 2020