Skip to content

Services, Wiki-Artikel, Blog-Beiträge und Glossar-Einträge durchsuchen

↑↓NavigierenEnterÖffnenESCSchließen
Logitech Hardware - Vulnerability still Exploitable!
Offensive Security

Logitech Hardware - Vulnerability still Exploitable!

The latest firmware update is intended to close a security hole in Logitech hardware devices that allows access to wireless keyboards or mice. However, the upda...

Vincent Heinen Vincent Heinen Abteilungsleiter Offensive Services
Updated: October 9, 2024 3 Min. read
OSCP+ OSCP OSWP OSWA

TL;DR

A Logitech firmware patch for its Unifying wireless receiver closed one attack vector - reading the encryption key via USB in about one second - but left a critical gap: the firmware can be downgraded to the vulnerable version, requiring only 30 seconds of physical access instead. With the encryption key, an attacker within radio range can decrypt and inject commands to the computer via forged wireless signals. Mitigations: never leave a computer unattended, always lock the screen when stepping away, and keep firmware updated.

Table of Contents (4 sections)

The latest firmware update is intended to close a security hole in Logitech hardware devices that allows access to wireless keyboards or mice. However, the update did not completely close this vulnerability.

Take advantage of the Logitech security patch

The patch prevents the encryption key from being read out via USB. For this the attacker needs a short access to the computer to read this code. The code is used to encrypt the various commands. This encrypts the communication between the computer and the radio. Due to the patch it is no longer possible to read the code from the unifiying receiver via USB, so the firmware update is successful under this aspect.

Vulnerability of Logitech Hardware

The security patch itself is currently secure and offers no known vulnerability. However, Logitech has forgotten in the firmware update that the attacker can reset the system to an older version. If the attacker succeeds in resetting the system to an older firmware, he can exploit the known vulnerability and read the encryption key via USB. Since it is possible to reset the firmware, the firmware update is invalid. The only disadvantage that the attacker now has is that he now needs about 30 seconds access to the computer instead of 1 second.

The Danger for Logitech Hardware Users

If someone has managed to copy their own encryption code, they can now read all the commands I give to the radios. The attacker can do this because he can read the encrypted communication between my radios and the computer when he is in the environment. The encryption code can decrypt the communication and the attacker can read the commands in plain text. The bigger problem is that the attacker can now send his own commands. He can encrypt these commands with the encryption code and the computer then processes these commands. This gives an attacker full access via their own radios.

Your own Logitech security patch

If you are interested in what such an attack looks like live and what possibilities an attacker has now, then you should take a look at our live hacking page. We will show you live how fast the attack works and what can happen after a successful attack, both from the attacker’s and the victim’s point of view. In addition, we present some of the ways Live can protect you against such an attack. To avoid becoming a victim of such an attack, you should follow the advice below:

  • Protect devices from unauthorized access (do not allow anyone else to access your computer)
  • Lock your computer (30 seconds is enough, so lock your computer when leaving the room)
  • Keep your devices up to date (known vulnerabilities will be closed by updates)

Next Step

Our certified security experts will advise you on the topics covered in this article — free and without obligation.

Free · 30 minutes · No obligation

Share this article

About the author

About the Author

Vincent Heinen
Vincent Heinen

Abteilungsleiter Offensive Services

E-Mail

M.Sc. IT-Sicherheit mit über 5 Jahren Erfahrung in offensiver Sicherheitsanalyse. Leitet die Durchführung von Penetrationstests mit Spezialisierung auf Web-Applikationen, Netzwerk-Infrastruktur, Reverse Engineering und Hardware-Sicherheit. Verantwortlich für mehrere Responsible Disclosures.

OSCP+ OSCP OSWP OSWA
Certified ISO 27001ISO 9001AZAVBSI

Cookielose Analyse via Matomo (selbst gehostet, kein Tracking-Cookie). Datenschutzerklärung