Tech

AI agent exposes critical security flaws in common USB and WiFi peripherals

A developer’s use of the Claude Opus 5 model to reverse engineer five consumer devices revealed plaintext command shells, defeatable activity lights, and unauthenticated network access, raising fresh concerns about hardware security.

Editorial persona
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: Hacker News · View original source
Tech
No image available
Technology

A developer has utilised the Claude Opus 5 artificial intelligence agent to reverse engineer the firmware of five common USB and WiFi peripherals, uncovering significant security vulnerabilities in everyday hardware. The investigation, which targeted a Shure MV7 microphone, an Insta360 Link webcam, an Elgato Key Light Mini, an ASUS ROG Swift PG42UQ monitor, and an Elgato Cam Link 4K capture device, required approximately 13 hours of AI processing time and 98 user prompts over a two-week period.

The findings suggest that modern peripherals are increasingly susceptible to firmware implants and remote exploitation. In the case of the Shure MV7 microphone, the AI identified a full plaintext command shell accessible via USB HID. This shell features 48 distinct commands and a weak authentication system where the top-tier privilege is granted by a simple string comparison, allowing users to disable the touch panel or drive the mute LED independently of the actual microphone state.

The Insta360 Link webcam presented a different set of risks, with the developer successfully patching out the activity LED to allow recording without visual indication. While the device’s gimbal still physically deflects when not in use, the ability to suppress the green recording light mirrors the classic "iSeeYou" exploit, raising privacy concerns for users who rely on visual cues to determine when a camera is active.

Perhaps the most significant finding involved the Elgato Key Light Mini, a WiFi-connected smart light. Although the device uses Ed25519 signature validation for firmware updates, the AI discovered that this check can be bypassed via a specific HTTP POST request. This vulnerability allows for unauthenticated memory writes over the network, meaning anyone on the same WiFi network could potentially update the firmware without a legitimate signature, a flaw the developer tested by successfully changing the device name.

The ASUS ROG Swift PG42UQ monitor was found to have effectively no significant protection, allowing the "pixel cleaning" warning to be patched out, though the developer has not yet flashed the modified firmware to the hardware. Meanwhile, the Elgato Cam Link 4K capture device allows full firmware updates without protection and exposes internal I2C bus registers via a vendor HID protocol, providing direct access to the internal HDMI receiver registers.

The developer noted that peripherals are ideal targets for agentic reverse engineering because they function as small computers with data connections to the host and usually possess firmware update mechanisms. While this openness improves interoperability, it raises the operating assumption that any device attached to a computer could have had a malicious firmware implant performed, a task that previously required significant per-model investment and was stereotyped as a state actor activity.

Continue reading

More from Tech

Read next: Apple reportedly developing iPhone game controllers under Beats brand
Read next: Tesla-linked DNS setup allegedly sends Assetnote scans to volunteer NTP server
Read next: Google criticised over YouTube advert flagged as deceptive