Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 China made tool containing security concerns!

views
     
TSkilldavid
post Dec 9 2025, 08:17 AM, updated 2w ago

Senior Satire Officer
******
Senior Member
1,638 posts

Joined: Aug 2005
From: Vault 13



Researcher finds Chinese KVM has undocumented microphone, communicates with China-based servers — Sipeed's nanoKVM switch has other severe security flaws and allows audio recording, claims researcher

Researcher finds Chinese KVM has undocumented microphone, communicates with China-based servers — Sipeed's nanoKVM switch has other severe security flaws and allows audio recording, claims researcher

The compact RISC-V board, which arrived on the market last year as a budget alternative to PiKVM, offers HDMI capture, USB HID emulation, remote power control, and browser-based access to a connected PC. It is beginning to show up in IT environments precisely because it requires no software on the target machine and can operate from BIOS to OS install.

The researcher says the device’s software stack exposes weak points from the moment it boots. Early units arrived with a pre-set password and open SSH access, a problem the researcher reported to Sipeed and which the company later corrected. The web interface still lacks basic protections, including CSRF defence and any mechanism to invalidate active sessions.

More troubling, the encryption key used to protect login passwords in the browser is hardcoded and identical across all devices. According to the researcher, this had to be explained to the developers “multiple times” before they acknowledged the issue.

The NanoKVM’s network behavior raises further questions, as it routes DNS queries through Chinese servers by default and makes routine connections to Sipeed infrastructure to fetch updates and a closed-source binary component. The key verifying that component is stored in plain text on the device, and there is no integrity check for downloaded firmware.

The underlying Linux build is also a heavily pared-down image without common management tools, yet it includes tcpdump and aircrack, utilities normally associated with packet inspection and wireless testing rather than production hardware intended to sit on privileged networks.

All this, paired with the discovery of a tiny surface-mount microphone, should make any user suspicious of the device’s true intentions. The researcher says the microphone is not documented in product materials, yet the operating system includes ALSA tools such as amixer and arecord that can activate it immediately. With default SSH credentials still present on many deployed units, the researcher demonstrated that audio could be recorded and exfiltrated with minimal effort, and streaming that audio in real time would require only modest additional scripting.

Thankfully, because NanoKVM is nominally open source, community members have begun porting alternative Linux distributions, first on Debian and later Ubuntu. Reflashing requires opening the case and writing a new image to the internal microSD card, but early builds already support Sipeed’s modified KVM code. Physically removing the microphone is possible, though the component’s size and placement make it a fiddly job without magnification.
------

Pls be vigilant
jibpek
post Dec 9 2025, 08:40 AM

Enthusiast
*****
Junior Member
708 posts

Joined: Jul 2012
Where is the spy chip CCP planted inside ipong?
supermoto
post Dec 9 2025, 08:54 AM

Casual
***
Junior Member
387 posts

Joined: Dec 2010
china banyak pandai implant thing mcm bat sup in byd

This post has been edited by supermoto: Dec 9 2025, 08:55 AM
Rusty Nail
post Dec 9 2025, 09:02 AM

Why am I still here?
*******
Senior Member
4,884 posts

Joined: Jan 2003
From: Petaling Jaya



The researcher says the microphone is not documented in product materials

This is a big red flag. Why would a kvm even nerds microphone? Server room is noisy anyways, what are they listening for? If used in small office where work station is the server, habislah.

Added
Ok I can think of 1 use case for the mic. To listen to motherboard diagnostic beeps. Kinda cleaver actually. It should be documented tho.

This post has been edited by Rusty Nail: Dec 9 2025, 09:57 AM
SUSMsnine
post Dec 9 2025, 09:14 AM

New Member
*
Junior Member
26 posts

Joined: Dec 2010

what is KVM?
damonlbs
post Dec 9 2025, 09:20 AM

Casual
***
Junior Member
487 posts

Joined: May 2005
From: KL


better worry about your phone spying on you

This post has been edited by damonlbs: Dec 9 2025, 04:19 PM
COOLPINK
post Dec 9 2025, 09:22 AM

Look at all my stars!!
*******
Senior Member
3,666 posts

Joined: Oct 2010
Lol their explanation.
When they going to say camera is also part of KVM switches?

This post has been edited by COOLPINK: Dec 9 2025, 09:22 AM
Capt. Marble
post Dec 9 2025, 09:25 AM

Getting Started
**
Junior Member
222 posts

Joined: Jan 2019
From: Earth
I scared my screwdriver also communicate to China server. Macamlah WIndows does not sent telemetry data back to their servers without telling you.

This post has been edited by Capt. Marble: Dec 9 2025, 09:26 AM
kons
post Dec 9 2025, 09:28 AM

Конс
Group Icon
Moderator
6,181 posts

Joined: Oct 2004



nothing that cannot be blocked by firewall.

as long as proper firewall rules is in place.
TSkilldavid
post Dec 9 2025, 03:59 PM

Senior Satire Officer
******
Senior Member
1,638 posts

Joined: Aug 2005
From: Vault 13



Woi who go report me ?
This is not racial.
It is security awareness
andyng38
post Dec 9 2025, 04:02 PM

Look at all my stars!!
*******
Senior Member
2,402 posts

Joined: Jun 2007
KVM = Klang Valley Macha?
loserguy
post Dec 9 2025, 04:12 PM

On my way
****
Junior Member
500 posts

Joined: Dec 2019
QUOTE(Msnine @ Dec 9 2025, 09:14 AM)
what is KVM?
*
QUOTE(andyng38 @ Dec 9 2025, 04:02 PM)
KVM = Klang Valley Macha?
*
I think they are refering to the switch people use when they want to control different computers using the same keyboard and mouse. Used to be very common in the workplace.

The old ones don't have SSH access. Not sure if that is a good idea.

Edit: i googled it, Keyboard Video Mouse, lol hari ini baru saya tau

user posted image

This post has been edited by loserguy: Dec 9 2025, 04:15 PM
loserguy
post Dec 9 2025, 04:14 PM

On my way
****
Junior Member
500 posts

Joined: Dec 2019
QUOTE(kons @ Dec 9 2025, 09:28 AM)
nothing that cannot be blocked by firewall.

as long as proper firewall rules is in place.
*
No, this is bad practice. Basically bypasses most protections on the machine itself, leaving your network as the last line of defence.
keybearer
post Dec 9 2025, 04:18 PM

Casual
***
Junior Member
409 posts

Joined: Nov 2009
From: Internet


QUOTE(killdavid @ Dec 9 2025, 04:59 PM)
Woi who go report me ?
This is not racial.
It is security awareness
*
Lol wolf 'warriors' proving siapa paling glassheart punya group in /k
whyamiblack
post Dec 9 2025, 04:34 PM

Getting Started
**
Junior Member
70 posts

Joined: Feb 2014
QUOTE(Capt. Marble @ Dec 9 2025, 09:25 AM)
I scared my screwdriver also communicate to China server. Macamlah WIndows does not sent  telemetry data back to their servers without telling you.
*
So 2 wrong means right?
unknown_2
post Dec 9 2025, 04:35 PM

On my way
****
Junior Member
573 posts

Joined: Mar 2012


QUOTE(kons @ Dec 9 2025, 09:28 AM)
nothing that cannot be blocked by firewall.

as long as proper firewall rules is in place.
*
not really. all these big corporates masks these data collection as "diagnostic", or use the same domain for data collection/update/essential services.
then u cant block without effecting the function of the OS.
microsoft been sending data, even user pc screenshots back to microsoft for years, no 1 bats an eye pun.
JohnL77
post Dec 9 2025, 04:36 PM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(killdavid @ Dec 9 2025, 03:59 PM)
Woi who go report me ?
This is not racial.
It is security awareness
*
Who else? 18 Jan punya gang la.
yushin
post Dec 9 2025, 04:56 PM

Look at all my stars!!
*******
Senior Member
3,329 posts

Joined: Jan 2003
From: Selangor


go to reddit /homelab see people's response to the KVM mic thing.
https://www.reddit.com/r/homelab/comments/1...s_undocumented/

the homelab crowd reply feels more... interesting. hmmm

This post has been edited by yushin: Dec 9 2025, 05:12 PM
LemonHoneyIce
post Dec 9 2025, 05:10 PM

New Member
*
Junior Member
33 posts

Joined: Sep 2021
They were intended to sell the items to their own people, hence spying by CCP is inevitable, but foreign countries attracted by cheap cheap price all buy, ofcos came with these "features", but in the end upload to CCP server or not dunno la
TSkilldavid
post Dec 9 2025, 05:20 PM

Senior Satire Officer
******
Senior Member
1,638 posts

Joined: Aug 2005
From: Vault 13



QUOTE(keybearer @ Dec 9 2025, 04:18 PM)
Lol wolf 'warriors' proving siapa paling glassheart punya group in /k
*
Must be reasonable la.
Security concerns, this is not an accusation of spying.
Most likely sloppy implementation
vhs
post Dec 9 2025, 05:29 PM

Getting Started
**
Junior Member
90 posts

Joined: May 2022
Sounds like shitty noob design instead of a sophisticated spying design tongue.gif
diffyhelman2
post Dec 9 2025, 05:31 PM

Enthusiast
*****
Junior Member
863 posts

Joined: Apr 2019
QUOTE(killdavid @ Dec 9 2025, 05:20 PM)
Must be reasonable la.
Security concerns, this is not an accusation of spying.
Most likely sloppy implementation
*
in before sendiri open baiting tered play innocent... whistling.gif
brian81st
post Dec 9 2025, 05:35 PM

New Member
*
Junior Member
46 posts

Joined: Oct 2008
QUOTE(killdavid @ Dec 9 2025, 03:59 PM)
Woi who go report me ?
This is not racial.
It is security awareness
*
the source code is open. you can study it or even use your own source code.

which electrical stuff you have have open source code?

just replying to your security concern.

i dont report people

This post has been edited by brian81st: Dec 9 2025, 05:35 PM
WhatMan
post Dec 9 2025, 05:38 PM

Regular
******
Senior Member
1,623 posts

Joined: Oct 2010


KVM lease of our worries when phone does it all the time.
ornehx
post Dec 9 2025, 05:42 PM

New Member
*
Newbie
40 posts

Joined: Jun 2006
Oh good tonite sing karaoke can share with CCP
vhs
post Dec 9 2025, 06:16 PM

Getting Started
**
Junior Member
90 posts

Joined: May 2022
QUOTE(Rusty Nail @ Dec 9 2025, 09:02 AM)
The researcher says the microphone is not documented in product materials

This is a big red flag. Why would a kvm even nerds microphone? Server room is noisy anyways, what are they listening for? If used in small office where work station is the server, habislah.

Added
Ok I can think of 1 use case for the mic. To listen to motherboard diagnostic beeps. Kinda cleaver actually. It should be documented tho.
*
It is voice activated assistant. "Hello Alexa switch to second PC"
Avex
post Dec 9 2025, 07:36 PM

On my way
****
Junior Member
570 posts

Joined: Jan 2003
From: /k/ isle

all these riscV board are mainly for researchers to make proof of concept for products, never supposed to be used in your company servers or data centers
loserguy
post Dec 9 2025, 07:53 PM

On my way
****
Junior Member
500 posts

Joined: Dec 2019
QUOTE(brian81st @ Dec 9 2025, 05:35 PM)
the source code is open. you can study it or even use your own source code.

which electrical stuff you have have open source code?

just replying to your security concern.

i dont report people
*
Open source =/= 100% safe. It just means that it is there, not that there is actually anyone looking at it.

Only last year we had a case where somebody put something naughty in the source code for a very common utility.

https://en.wikipedia.org/wiki/XZ_Utils_backdoor
https://tekkix.com/articles/security/2025/0...e-largest-cyber

The kicker is this, the exploit got caught, not because there was a robust process and a bunch of experienced eyeballs scanning it. But because a nerd noticed a half second delay. A half second delay. This was utter, complete, sheer dumb luck. Without that guy, all of us would be unknowingly running linux OSes with this backdoor built in.

Edit: honestly, who knows what else the alphabet agencies have slipped in over the years.

This post has been edited by loserguy: Dec 9 2025, 07:55 PM

 

Change to:
| Lo-Fi Version
0.0214sec    0.58    5 queries    GZIP Disabled
Time is now: 19th December 2025 - 09:40 PM