Case Study: A Smart Irrigation System Anyone Could Control
We tested a smart irrigation system: a broken MQTT setup let us see and switch the devices of other customers, and locate where they are installed.
Zyberum Security Team · Published · 4 min read
Smart irrigation sounds harmless: valves, a controller, an app. We tested such a system and ended up with control over devices that were not ours, and a map of where they are.
What we tested
- the controller and its firmware
- the mobile app
- the cloud service
- the MQTT connection that carries commands and status messages
What we found
MQTT was broken
The system used MQTT to connect devices, app and cloud. The setup did not separate customers from each other. From our own account we could see the devices of other customers, including their status messages.
We could switch them
Seeing was not the end of it. We could also send commands: open valves, start watering, change settings, on systems that belonged to other people.
We could find them
The messages and API responses contained enough information to geolocate the devices. An attacker would know which device is where.
Why it matters
Put together: a list of devices, their locations, their activity, and the ability to control them remotely. That is water damage and cost at scale, and it is location data about private homes and businesses.
And as with most IoT findings of this kind, nothing here required breaking encryption or exploiting memory bugs. The system answered questions it should have refused.
What manufacturers should take from it
- Give every device its own identity. Its own credentials, not a shared one from the firmware.
- Restrict topics on the broker. A client may only read and write its own topics. Wildcard subscriptions for normal clients must be impossible.
- Do not put location into messages that do not need it. Data that is not sent cannot leak.
- Check authorization in the cloud, too. The same ownership check belongs in every API call.
- Monitor the broker. One client subscribing to everything is an incident, and it should raise an alarm.
These are exactly the points that the RED cybersecurity requirements (EN 18031) and the Cyber Resilience Act now make mandatory for connected products.
We test devices, their apps and their cloud as one system. See IoT security testing or hardware pentests, or check what a test costs.
FAQ
Frequently asked questions
What is MQTT and why is it a risk?
MQTT is a lightweight messaging protocol used by many IoT products: devices and apps publish and subscribe to topics on a central broker. If the broker does not restrict which topics a client may use, any connected client can read and send messages for every device.
Is a garden irrigation system really a security problem?
Yes. Whoever controls it can cause water damage and costs, and the location data tells an attacker where the devices are installed and, from their activity, when people are away. The same product families are also used in agriculture and on commercial sites.