Researchers find severe vulnerabilities in garage door openers and other smart devices

TechSpot is about to celebrate its 25th anniversary. TechSpot means tech analysis and advice you can trust.

PSA: A security researcher and US authorities discovered multiple severe vulnerabilities rendering Nexx smart security systems virtually toothless. Those using their devices should find another solution ASAP since Nexx has been radio-silent for two years.

Researcher Sam Sabetan, cooperating with the US Department of Homeland Security (DHS) and the Cybersecurity and Infrastructure Security Agency (CISA), recently published several severe security risks involving Nexx smart home systems. The vulnerabilities allow attackers to quickly seize complete control over garage door openers, smart plugs, and alarm systems from anywhere on Earth.

Nexx offers devices that let users open garage doors, toggle home security systems, and switch smart power outlets on or off through a smartphone app. Earlier this year, Sabetan discovered that the devices’ connections to the company’s cloud use extremely weak security.

When a user registers the Nexx app with the company’s cloud, its servers send a password to the app and device, establishing the connection. Unfortunately, the password is identical for all users. Furthermore, it’s freely available in Nexx’s API and publicly available in each device’s firmware.

Equipped with the password, an attacker with access to Nexx’s servers can remotely open any garage door and switch off devices connected to smart plugs. They can also see users’ email addresses, device IDs, first names, and last initials, allowing hackers to target specific people.

While the home alarm doesn’t suffer from this specific vulnerability, it has two equally serious problems. Any registered Nexx user with an alarm’s MAC address can take over that alarm, and the MAC address isn’t tricky to discover. Nexx’s server doesn’t verify bearer tokens, potentially letting bad actors send signals to users’ alarms. All Nexx alarm MAC addresses begin with the same digits – 7C 9E BD F4 – making the remainder of the address easy to brute-force. Additionally, a hacker with the MAC address can hijack a registered alarm by reregistering it under a rogue account, removing access from the original user, and giving the attacker complete control over the security system.

Sabetan, the DHS, and CISA have tried contacting Nexx on multiple occasions since January with no success. The company’s mobile apps are still functional. Its social media accounts and website are still online but have logged no activity since 2021. More concerning is that Nexx’s official Twitter posted a tweet in April 2021 appearing to advertise a Web3 studio, suggesting someone else gained control of the account.

Despite signs indicating Nexx has dropped off the face of the Earth, the company’s online store still operates, and the garage door opener remains available on Amazon. Even if few new customers buy Nexx’s products, Sabetan estimates their vulnerabilities endanger 40,000 devices and 20,000 active accounts. It suggests users immediately stop using the devices and try to contact Nexx for refunds. The CISA recommends disconnecting the devices from the internet, isolating them from business networks, or accessing them through VPN.

If Nexx is defunct, it represents another case of what happens to IoT devices when manufacturers and software developers abandon their products.

Read More
Randy Pecora

Latest

Martin Scorsese has officially joined the AI camp and it’s not what anyone expected

Martin Scorsese has partnered with AI startup Black Forest Labs to use generative AI for storyboarding Martin Scoresese Everett Collection / Shutterstock.com Hollywood’s complicated romance with artificial intelligence just got a whole lot more interesting. Martin Scorsese, the 83-year-old director behind Goodfellas, Raging Bull, and The Departed, has signed on as a partner and adviser

Trump quietly signs a downsized AI executive order asking companies to voluntarily submit models for review 30 days before release

President Trump signed an executive order on Tuesday establishing a voluntary framework for government review of frontier AI models before public release, ending weeks of internal White House conflict over how aggressively to regulate the technology. The order, titled “Promoting Advanced Artificial Intelligence Innovation and Security,” was signed privately without the usual livestream or public ceremony, a

Poland will introduce a “sovereignty test” for government tech purchases as Tusk warns AI dependency has reached dangerous proportions

TL;DR Polish PM Donald Tusk announced a “sovereignty test” for significant government technology purchases and annual IT independence reports, warning that Poland’s dependency on foreign digital infrastructure demands urgent policy action. Polish Prime Minister Donald Tusk has announced that Poland will introduce a “sovereignty test” for significant government purchases of technology solutions, warning that the

How small businesses can leverage AI

Case study Sam Finnegan-Dehn works in fundraising for a charity, but he moonlights as a math and philosophy tutor for university students from his home in London. Through this part-time business, he can leverage his degrees in philosophy and share his love of the subject with clients. But meeting with students is only a fraction

Newsletter

Don't miss

Martin Scorsese has officially joined the AI camp and it’s not what anyone expected

Martin Scorsese has partnered with AI startup Black Forest Labs to use generative AI for storyboarding Martin Scoresese Everett Collection / Shutterstock.com Hollywood’s complicated romance with artificial intelligence just got a whole lot more interesting. Martin Scorsese, the 83-year-old director behind Goodfellas, Raging Bull, and The Departed, has signed on as a partner and adviser

Trump quietly signs a downsized AI executive order asking companies to voluntarily submit models for review 30 days before release

President Trump signed an executive order on Tuesday establishing a voluntary framework for government review of frontier AI models before public release, ending weeks of internal White House conflict over how aggressively to regulate the technology. The order, titled “Promoting Advanced Artificial Intelligence Innovation and Security,” was signed privately without the usual livestream or public ceremony, a

Poland will introduce a “sovereignty test” for government tech purchases as Tusk warns AI dependency has reached dangerous proportions

TL;DR Polish PM Donald Tusk announced a “sovereignty test” for significant government technology purchases and annual IT independence reports, warning that Poland’s dependency on foreign digital infrastructure demands urgent policy action. Polish Prime Minister Donald Tusk has announced that Poland will introduce a “sovereignty test” for significant government purchases of technology solutions, warning that the

How small businesses can leverage AI

Case study Sam Finnegan-Dehn works in fundraising for a charity, but he moonlights as a math and philosophy tutor for university students from his home in London. Through this part-time business, he can leverage his degrees in philosophy and share his love of the subject with clients. But meeting with students is only a fraction

Jury acquits 2 business executives of bribing Navy admiral for government contract

A federal jury has acquitted two business executives of charges that they conspired to bribe a retired four-star U.S. Navy admiral, who is now serving a six-year prison sentence for his conviction on corruption charges By MICHAEL KUNZELMAN Associated Press WASHINGTON -- A federal jury has acquitted two business executives of charges that they conspired

US Business Leaders Optimistic About China Cooperation, Emphasize Importance of Chinese Market

© 2026 China Money Network. All Rights Reserved. Disclaimer: The views, opinions, forecasts, and statements made by our hosts and guests are the personal views of those respective individuals and may or may not be either endorsed or accepted by China Money Network Limited or the companies with which these individuals are employed.

Tesla’s Business Has Become Much More Diversified in Just the Past Five Years. Does That Make Its Stock a Better Buy Today?

Key Points Tesla's energy generation and storage segment generated 27% revenue growth last year. The company's non-automotive segments were able to help offset a double-digit decline in auto revenue in 2025. These 10 stocks could mint the next wave of millionaires › Tesla (NASDAQ: TSLA) is known for its electric vehicles (EVs), and while they