A security assessment of the Plugwise Anna connected thermostat uncovered multiple weaknesses in the device and its supporting infrastructure, including an exposed production UART debug interface that provided U-Boot access and enabled firmware extraction from the device’s flash. Reverse engineering of the thermostat’s customized OpenWrt firmware showed that Plugwise’s encrypted Lua application could be decrypted because the key was embedded in the interpreter, exposing source code and increasing the risk of further compromise through the web interface.
The researcher also found that the thermostat relied on reverse SSH tunnels to a Plugwise relay server and was able to retrieve a private key through the device API, leading to interactive shell access on an outdated Amazon Linux relay host. A scan of the relay server identified 205 publicly reachable reverse SSH tunnels into deployed customer devices, unnecessarily exposing home-network systems. According to the disclosure timeline, the issues were reported to Plugwise in June 2018, and the company hardened its back-end servers and relay users by October 2018.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Codean Labs publicly disclosed its findings on the Plugwise Anna thermostat, detailing device-side weaknesses and exposure created by publicly reachable reverse SSH tunnels into deployed devices. The original post was published on 2018-11-07.
By 2018-10-07, Plugwise had hardened its back-end servers and relay user configuration in response to the reported thermostat security issues. This addressed the exposed relay infrastructure described in the assessment.
A security assessment of the Plugwise Anna IoT thermostat uncovered weaknesses including exposed UART debug access, recoverable firmware and Lua code, and insecure reverse SSH tunnel design. The issues were reported to Plugwise on 2018-06-16.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.