-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Advisory ID: SYSS-2024-044 Product: eLinkSmart Hidden Smart Cabinet Lock Manufacturer: eLinkSmart EU (Vertix Tech BVBA) Vulnerability Type: CWE-862: Missing Authorization Risk Level: High Solution Status: Open Manufacturer Notification: 2024-05-22 Solution Date: tba. Public Disclosure: 2024-07-12 CVE Reference: CVE-2024-36438 Author of Advisory: Sebastian Auwärter, SySS GmbH ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Overview: eLinkSmart Cabinet Lock is a cabinet lock which uses NFC cards for unlocking. The manufacturer describes the product as follows (see [1]): "This smart lock can be unlocked through the APP and RFID card, and supports an NFC function, making your unlocking more convenient and fast, without worrying about forgetting the password or key. This concealment cabinet lock is made of high-quality materials, and the unique installation design with security features such as anti-prying and anti-vandalism, which can provide higher security and protect your property and privacy." Due to the used MIFARE Classic 1K Cards (ISO14443-3), the Smart Cabinet Lock is vulnerable to card duplication and other (see [2]) attacks. It is possible to copy and emulate the key cards using either "magic cards" which allow copying the serial number or to emulate the cards using hardware like the Flipper Zero. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Vulnerability Details: The used technology of the cards is easily replicated using magic cards or emulation hardware like a Flipper Zero. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Proof of Concept (PoC): Copying the card: Using a Flipper Zero, go to "NFC" -> "Read", then hold the card to the back of the Flipper device until the card information appears. Press right for "More", then save the dump to a file. Emulating the card: After copying the card, go to "NFC" -> "Saved", choose the saved dump file, then "Emulate". Touch the reader of the lock with the back of the Flipper and it will open. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Solution: Use a more secure type of NFC card and enable the security features. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Disclosure Timeline: 2024-05-22: Vulnerability discovered 2024-05-22: Vulnerability reported to manufacturer 2024-05-28: Reminder sent to the manufacturer 2024-06-19: Reminder sent to the manufacturer 2024-07-12: Public disclosure of vulnerability tba.: Patch released by manufacturer ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ References: [1] Product website for eLinkSmart Hidden Smart Cabinet Lock https://www.elinksmart.net/product/elinksmart-hidden-smart-cabinet- lock-rfid-electronic-keyless-bluetooth-diy-child-safety-lock-for- concealment-furniture-liquor-cabinet-locker-pantry-drawer-cupboard/ [2] https://web.archive.org/web/20220102193453/http://www.cs.ru.nl /~flaviog/publications/Pickpocketing.Mifare.pdf [3] https://flipperzero.one/ [4] SySS Security Advisory SYSS-2024-044 https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/ SYSS-2024-044.txt [5] SySS Responsible Disclosure Policy https://www.syss.de/en/responsible-disclosure-policy ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Credits: This security vulnerability was found by Sebastian Auwärter of SySS GmbH. E-Mail: sebastian.auwaerter@syss.de LinkedIn: https://de.linkedin.com/in/sebastian-auw%C3%A4rter-156035305 Public Key: https://www.syss.de/kontakt/pgp-keys Key Fingerprint: F98C 3E12 6713 19D9 9E2F BE3E E9A3 0D48 E2F0 A8B6 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Disclaimer: The information provided in this security advisory is provided "as is" and without warranty of any kind. Details of this security advisory may be updated in order to provide as accurate information as possible. The latest version of this security advisory is available on the SySS website. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Copyright: Creative Commons - Attribution (by) - Version 3.0 URL: http://creativecommons.org/licenses/by/3.0/deed.en -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE+Yw+EmcTGdmeL74+6aMNSOLwqLYFAmaOKuEACgkQ6aMNSOLw qLZXDA/5AaJDP6gcnuK5bztnxMhPrj4BXfWjmDxhNniZkziuCCcoy+9SFwph/DN2 Wv7sFQCdsg3zsRrs1OjIHQf5fqevO5s0eFiCOIHh5R3EuAqibiv4nYGI86v9Tnw4 B//d16ohn3jPgtDwE4AE1RdwVKr7V3mQadOsjvvHUYTJyH18NUWOSfNN35O4c7lK nJY3ozLGt08E8JndQP2ve67t1HDuZaZI7lKYtXcDYwEFtkQMN//FTKH4lLWC13aV x3lFgwS6kVsiX+54v1Na7mGUn0umt6knDz4Im7E75Nut18Yf+nENQEaLAOJPk0jj M5I86Nb4SBGVDFfPj4qSMIcLiMCKH2LZFnAu/Zxj4ykPA8hveCTGdnsmyP47MmG0 rOOgD6Dwuzu4i+gL4vNHrzu9mmK3BCotPvXy5CGyBeaP6TNtDhFjLmUkkNe4CLK2 q4yyea15CNzdGvPQZbPBptbOLA1hpeYpLN1aDigZejB07OyGtYdorQ+HlAK3AORI NT9+YjlcAPQj9Jbm32eF4020ZWFN142+YePmp8pougcoo67/qzzkHGpQvbSJS2Lc 12W/RX0Fcb1PiyddcUfNibkDDuCRTIq5bKxopAKaJ5rCsnywyLc/0TPTllHjqzrf gazpGiEW7vAhHO0mw/pBtczPg+spmbDhcbPSzUrjN4pF6NKSb20= =uiu0 -----END PGP SIGNATURE-----