(Pwn2Own) Amazon Smart Plug OTA Update Process Out-Of-Bounds Write Remote Code Execution Vulnerability
Vulnerability Details
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Amazon Smart Plug. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the processing of OTA updates. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of data structure. An attacker can leverage this vulnerability to execute code in the context of the device.
Additional Details
Fixed in Amazon Smart Plug version is 3.1.212
https://www.amazon.com/gp/help/customer/display.html?nodeId=T7PZ186qF8gift84NG
Disclosure Timeline
- 2025-11-05 - Vulnerability reported to vendor
- 2026-08-12 - Coordinated public release of advisory
- 2026-08-12 - Advisory Updated
Credit
Team Neodyme (@Neodyme)