Security misconfiguration in IKEA DIRIGERA smart hub web server exposes large parts of the root filesystem (GCVE-2342-2026-1)
IKEA produces smart home devices and their newest generation uses the central DIRIGERA smart hub. After extracting the firmware, we started hunting for vulnerabilities of the device and found: An unauthenticated attacker on the network can download large parts of the files from the DIRIGERA hub root filesystem. This affects files that are accessible to the service user license-server. These include binaries, firmware files, API keys and in general a lot of proprietary code written by Inter IKEA Systems.