TecnoArtesanos Tech BlogTecnoArtesanos Tech Blog

Blog

0
Sergio Morales
Monday, 10 March 2025 / Published in Uncategorized

Billions of Devices at Risk of Hacking & Impersonation Due to Hidden Commands

Tarlogic team giving their presentation during RootedCON.
Tarlogic team giving their presentation during RootedCON. Image: Tarlogic

Billions of devices worldwide rely on a widely used Bluetooth-Wi-Fi chip that contains undocumented “hidden commands.” Researchers warn these commands could be exploited to manipulate memory, impersonate devices, and bypass security controls.

Contents
    • Must-read security coverage
  • Hidden Bluetooth commands and potential exploits
    • What are the barriers to entry for these exploits?
  • What happens next?

ESP32, manufactured by a Chinese company called Espressif, is a microcontroller that enables Bluetooth and Wi-Fi connections in numerous smart devices, including smartphones, laptops, smart locks, and medical equipment. Its popularity is partly due to its low cost, with units available for just a few dollars.

Must-read security coverage

Hidden Bluetooth commands and potential exploits

Researchers at security firm Tarlogic discovered 29 undocumented Host Controller Interface commands within the ESP32’s Bluetooth firmware. These commands enable low-level control over some Bluetooth functions, such as reading and writing memory, modifying MAC addresses, and injecting malicious packets, according to Bleeping Computer, which attended Tarlogic’s presentation at RootedCON.

SEE: Zscaler Report: Mobile, IoT, and OT Cyber Threats Surged in 2024

While these functions aren’t inherently malicious, bad actors could exploit them to stage impersonation attacks, introduce and hide backdoors, or modify device behavior — all while bypassing code audit controls. Such incidents could lead to a supply chain attack targeting other smart devices.

“Malicious actors could impersonate known devices to connect to mobile phones, computers and smart devices, even if they are in offline mode,” the Tarlogic researchers wrote in a blog post. “For what purpose? To obtain confidential information stored on them, to have access to personal and business conversations, and to spy on citizens and companies.”

What are the barriers to entry for these exploits?

Despite the risks, there are barriers to entry for exploiting these commands, which distinguishes them from typical backdoor vulnerabilities. Attackers would need physical access to the smart device’s USB or UART interface, or they would need to have already compromised the firmware through stolen root access, pre-installed malware, or other vulnerabilities to exploit the commands remotely.

What happens next?

Tarlogic researchers Miguel Tarascó Acuña and Antonio Vázquez Blanco discovered the vulnerable HCI commands using BluetoothUSB, a free hardware-independent, cross-platform tool that enables access to Bluetooth traffic for security audits and testing.

These hidden commands are likely hardware-debugging Opcode instructions that were unintentionally left exposed; TechRepublic has contacted Espressif to confirm but the company has yet to respond as of writing. The company’s response will be crucial in determining whether firmware updates or mitigations will be released to secure affected devices.

What you can read next

Trump cambia estrategia de aranceles para repatriar la producción automotriz
Redes sociales y salud mental: lo que la ciencia sabe sobre su impacto en niñas, niños y adolescentes
Stargate tendrá la capacidad de siete reactores nucleares con esta nueva alianza de OpenAI

Recent Posts

  • Los agentes de IA rebeldes no son malvados, solo quieren complacernos
  • Dime cómo prompteas y la IA te dirá quién eres
  • La primicia ahora la tienen los periodistas de IA. Spoiler: son malos reporteros
  • El reto de las empresas mexicanas ya no es la adopción de IA, sino aprender a aprovecharla
  • Bienvenidos a la era de la computación hecha con cerebros de verdad

Recent Comments

  1. A WordPress Commenter on Welcome to My Tech Blog – A New Chapter in Innovation

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • August 2016

Categories

  • Uncategorized

Recent Posts

  • Los agentes de IA rebeldes no son malvados, solo quieren complacernos

    Que los agentes de IA vayan libres hackeando ot...
  • Dime cómo prompteas y la IA te dirá quién eres

    A finales de 2022, cuando OpenAI lanzó ChatGPT,...
  • La primicia ahora la tienen los periodistas de IA. Spoiler: son malos reporteros

    En la conferencia de seguridad Black Hat celebr...
  • El reto de las empresas mexicanas ya no es la adopción de IA, sino aprender a aprovecharla

    La adopción de la inteligencia artificial (IA) ...
  • Bienvenidos a la era de la computación hecha con cerebros de verdad

    Te voy a contar un secreto. Cada célula de tu c...

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • August 2016

Categories

  • Uncategorized

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Kallyas

The #1 Multi-Purpose theme with a Powerful Visual Page Builder that you’ll actually enjoy.

Newsletter

 

sociall

 

Company

Customer

The #1 WordPress theme with a Powerful Visual Page Builder that you'll actually enjoy.

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum.

Feed with such ID does not exist

Made with  ♥  by Hogash Studios. All Rights Reserved © 2016.

TOP