{"id":740,"date":"2026-04-13T12:04:34","date_gmt":"2026-04-13T10:04:34","guid":{"rendered":"https:\/\/www.hardwaresecurity.it\/?p=740"},"modified":"2026-04-13T12:07:25","modified_gmt":"2026-04-13T10:07:25","slug":"hacking-a-pos-with-whidboard","status":"publish","type":"post","link":"https:\/\/www.hardwaresecurity.it\/?p=740","title":{"rendered":"Hacking a POS with WHIDBOARD"},"content":{"rendered":"\n<p class=\"has-text-align-center\">Some time ago I was shopping around the city when I stumbled on an interesting POS (Point Of Sale). While the cashier was preparing the shopping bag I quickly took my phone and snapped a couple of photos for future reference\u2026<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/collage-1024x768.jpg\" alt=\"collage\" class=\"wp-image-747\" style=\"width:361px;height:auto\" title=\"Hacking a POS with WHIDBOARD\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/collage-1024x768.jpg 1024w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/collage-300x225.jpg 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/collage-768x576.jpg 768w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/collage-1536x1152.jpg 1536w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/collage-2048x1536.jpg 2048w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/collage-600x450.jpg 600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">Once home, I started taking a closer look at the labels underneath the POS and immediately realized one interesting thing\u2026 an FCC ID was clearly visible (i.e. <em>SEKMA512<\/em>)! \ud83d\ude0e<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"431\" height=\"291\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-2.jpeg\" alt=\"image\" class=\"wp-image-748\" title=\"Hacking a POS with WHIDBOARD\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-2.jpeg 431w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-2-300x203.jpeg 300w\" sizes=\"auto, (max-width: 431px) 100vw, 431px\" \/><\/figure>\n\n\n\n<p><strong>Passive RECON \u2013 OSINT Time!<\/strong><\/p>\n\n\n\n<p class=\"has-text-align-center\">With that piece of information, I was able to quickly get more details about this new DUT (Device Under Test) even without owning one (yet).<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"439\" height=\"438\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-2.png\" alt=\"image\" class=\"wp-image-749\" title=\"Hacking a POS with WHIDBOARD\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-2.png 439w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-2-300x300.png 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-2-150x150.png 150w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-2-100x100.png 100w\" sizes=\"auto, (max-width: 439px) 100vw, 439px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">Within the FCC database I was able to get more details about internal PCBs, how the device operates and if there are any anti-tampering features that will prevent hardware hacking attempts.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"301\" height=\"263\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-3.png\" alt=\"image\" class=\"wp-image-750\" title=\"Hacking a POS with WHIDBOARD\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"623\" height=\"230\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-4.png\" alt=\"image\" class=\"wp-image-751\" title=\"Hacking a POS with WHIDBOARD\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-4.png 623w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-4-300x111.png 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-4-600x222.png 600w\" sizes=\"auto, (max-width: 623px) 100vw, 623px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"485\" height=\"409\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-5.png\" alt=\"image\" class=\"wp-image-752\" title=\"Hacking a POS with WHIDBOARD\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-5.png 485w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-5-300x253.png 300w\" sizes=\"auto, (max-width: 485px) 100vw, 485px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">In particular, while reviewing its manual, I was able to confirm that indeed this POS (As any other similar device that handles credit cards data) has some countermeasures in place to prevent threat actors from physically tampering with the circuit board, as shown in the images above.<\/p>\n\n\n\n<p class=\"has-text-align-center\">However, I did not give up and continued looking around the FCC Database documents to have a better understanding of the whole DUT and complete my initial threat model, looking for potential entry-points.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"623\" height=\"492\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-8.png\" alt=\"image\" class=\"wp-image-755\" style=\"width:431px;height:auto\" title=\"Hacking a POS with WHIDBOARD\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-8.png 623w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-8-300x237.png 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-8-600x474.png 600w\" sizes=\"auto, (max-width: 623px) 100vw, 623px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">As you can see from the image above, the main PCB has a number of test points. Some of them captured my interest, especially because they appeared to be externally accessible without opening the POS enclosure \u2014 meaning they could be probed without triggering the anti-tamper mechanisms that would wipe the device\u2019s memory.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"350\" height=\"250\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-6.png\" alt=\"image\" class=\"wp-image-753\" title=\"Hacking a POS with WHIDBOARD\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-6.png 350w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-6-300x214.png 300w\" sizes=\"auto, (max-width: 350px) 100vw, 350px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">Now that I got some potential entry-points, was time to purchase some samples online\u2026<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"477\" height=\"359\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-7.png\" alt=\"image\" class=\"wp-image-754\" style=\"width:400px;height:auto\" title=\"Hacking a POS with WHIDBOARD\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-7.png 477w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-7-300x226.png 300w\" sizes=\"auto, (max-width: 477px) 100vw, 477px\" \/><\/figure>\n\n\n\n<p><strong>Active RECON \u2013 Pins Enumeration with <a href=\"https:\/\/lab401.com\/en-it\/products\/whidboard-pro\" data-type=\"link\" data-id=\"https:\/\/lab401.com\/en-it\/products\/whidboard-pro\">WHIDBOARD<\/a><\/strong><\/p>\n\n\n\n<p class=\"has-text-align-center\">Few days later, the DUT sample arrived, and the first step was probing the test points with a multi-meter to identify which ones were electrically relevant. Having narrowed them down, I have then used the Logic Analyzer feature embedded into <a href=\"https:\/\/lab401.com\/en-it\/products\/whidboard-pro\" data-type=\"link\" data-id=\"https:\/\/lab401.com\/en-it\/products\/whidboard-pro\">WHIDBOARD<\/a> to see if any data was being output by the POS.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"451\" height=\"301\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-3.jpeg\" alt=\"image\" class=\"wp-image-756\" title=\"Hacking a POS with WHIDBOARD\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-3.jpeg 451w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-3-300x200.jpeg 300w\" sizes=\"auto, (max-width: 451px) 100vw, 451px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">After trying different pins, as you can see from the screenshot below, I eventually found the TX line of a UART debug interface. \ud83d\ude0e<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"72\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-9.png\" alt=\"image\" class=\"wp-image-757\" title=\"Hacking a POS with WHIDBOARD\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-9.png 624w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-9-300x35.png 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-9-600x69.png 600w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">Now it\u2019s time to fire the Pin Enumerator Feature of <a href=\"https:\/\/lab401.com\/en-it\/products\/whidboard-pro\" data-type=\"link\" data-id=\"https:\/\/lab401.com\/en-it\/products\/whidboard-pro\">WHIDBOARD<\/a> in order to find also the RX pin!<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"309\" height=\"307\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-4.jpeg\" alt=\"image\" class=\"wp-image-760\" title=\"Hacking a POS with WHIDBOARD\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-4.jpeg 309w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-4-300x298.jpeg 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-4-150x150.jpeg 150w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-4-100x100.jpeg 100w\" sizes=\"auto, (max-width: 309px) 100vw, 309px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"617\" height=\"94\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-10.png\" alt=\"image\" class=\"wp-image-758\" title=\"Hacking a POS with WHIDBOARD\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-10.png 617w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-10-300x46.png 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-10-600x91.png 600w\" sizes=\"auto, (max-width: 617px) 100vw, 617px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"638\" height=\"668\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-11.png\" alt=\"image\" class=\"wp-image-759\" title=\"Hacking a POS with WHIDBOARD\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-11.png 638w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-11-287x300.png 287w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-11-600x628.png 600w\" sizes=\"auto, (max-width: 638px) 100vw, 638px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">Leaving the DUT completing the booting process led to something <strong>truly unexpected<\/strong>\u2026<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"542\" height=\"735\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-12.png\" alt=\"image\" class=\"wp-image-761\" title=\"Hacking a POS with WHIDBOARD\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-12.png 542w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-12-221x300.png 221w\" sizes=\"auto, (max-width: 542px) 100vw, 542px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">Not only did this POS expose a fully functional UART interface outside its anti-tamper security boundary \u2014 indicating a failure in both threat modeling during R&amp;D and security validation before production \u2014 but this debug interface dropped straight into a root shell. \ud83d\udca5\ud83e\udd2f<\/p>\n\n\n\n<p><strong>Let\u2019s Get Our Hands Dirty \u2013 Interacting with the DUT as root<\/strong><\/p>\n\n\n\n<p class=\"has-text-align-center\">At this point, things escalated quickly. Using <a href=\"https:\/\/lab401.com\/en-it\/products\/whidboard-pro\" data-type=\"link\" data-id=\"https:\/\/lab401.com\/en-it\/products\/whidboard-pro\">WHIDBOARD<\/a> I had identified an exposed UART that led to full, UNAUTHENTICATED ROOT ACCESS\u2026<\/p>\n\n\n\n<p class=\"has-text-align-center\">What came next, was me exploring the device\u2019s file system, inspecting running processes, and understanding the DUT\u2019s internal architecture.<\/p>\n\n\n\n<p class=\"has-text-align-center\">Eventually, I exfiltrated the entire firmware via a USB flash drive using the following commands\u2026<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"168\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image.jpg\" alt=\"image\" class=\"wp-image-762\" title=\"Hacking a POS with WHIDBOARD\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image.jpg 624w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-300x81.jpg 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-600x162.jpg 600w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"414\" height=\"192\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-13.png\" alt=\"image\" class=\"wp-image-763\" title=\"Hacking a POS with WHIDBOARD\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-13.png 414w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-13-300x139.png 300w\" sizes=\"auto, (max-width: 414px) 100vw, 414px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"598\" height=\"864\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-1.jpg\" alt=\"image\" class=\"wp-image-764\" title=\"Hacking a POS with WHIDBOARD\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-1.jpg 598w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-1-208x300.jpg 208w\" sizes=\"auto, (max-width: 598px) 100vw, 598px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">And to prove the point that I was able to not only read the file system but also tamper it\u2026 I did make some changes\u2026 \ud83d\ude0e<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"468\" height=\"624\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-5.jpeg\" alt=\"image\" class=\"wp-image-765\" style=\"width:300px;height:auto\" title=\"Hacking a POS with WHIDBOARD\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-5.jpeg 468w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-5-225x300.jpeg 225w\" sizes=\"auto, (max-width: 468px) 100vw, 468px\" \/><\/figure>\n\n\n\n<p><strong>Active RECON \u2013 Network Scanning<\/strong><\/p>\n\n\n\n<p class=\"has-text-align-center\">At this point, out of curiosity, I also checked for open network services on the DUT\u2019s Ethernet interface. The results were alarming: Telnet Port 23\/TCP was OPEN\u2026 \ud83e\udd2f\ud83d\udca5<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"161\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-2.jpg\" alt=\"image\" class=\"wp-image-766\" style=\"width:477px;height:auto\" title=\"Hacking a POS with WHIDBOARD\" srcset=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-2.jpg 624w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-2-300x77.jpg 300w, https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-2-600x155.jpg 600w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">And yes\u2026 you could log into it (as root) WITHOUT password!<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"284\" height=\"254\" src=\"https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/image-3.jpg\" alt=\"image\" class=\"wp-image-767\" style=\"width:320px;height:auto\" title=\"Hacking a POS with WHIDBOARD\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">At this point I decided to check on Shodan if any of these POS were facing the internet. The result: at least 61 of them were exposed on the internet\u2026 \ud83d\ude4a\ud83d\ude49\ud83d\ude48<strong><\/strong><\/p>\n\n\n\n<p class=\"has-text-align-left\"><strong>Conclusions<\/strong><\/p>\n\n\n\n<p class=\"has-text-align-center\">This DUT was quite a surprise \u2014 in over a decade of POS security research, I had never encountered a device with this many compounding failures. Let\u2019s break down what went wrong and why it matters.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Multiple layers of defense-in-depth failure<\/strong><\/li>\n<\/ul>\n\n\n\n<p class=\"has-text-align-left\">This device exhibited at least four distinct, independently exploitable vulnerabilities: <\/p>\n\n\n\n<p class=\"has-text-align-left\">(1) externally accessible debug test points that bypass physical anti-tamper protections; <\/p>\n\n\n\n<p class=\"has-text-align-left\">(2) an active, unauthenticated UART console yielding root shell access; <\/p>\n\n\n\n<p class=\"has-text-align-left\">(3) Telnet on port 23\/TCP with passwordless root login on the network interface; <\/p>\n\n\n\n<p class=\"has-text-align-left\">(4) at least 61 instances discoverable via Shodan, exposed directly to the internet. <\/p>\n\n\n\n<p class=\"has-text-align-left\">Each one alone would be a critical finding. Together, they represent a systemic failure in the product\u2019s security lifecycle \u2014 from threat modeling and secure design, through implementation and pre-production testing.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Implications for payment infrastructure<\/strong><\/li>\n<\/ul>\n\n\n\n<p class=\"has-text-align-left\">A POS terminal with root-level read\/write filesystem access \u2014 reachable both physically and over the network \u2014 opens the door to firmware backdooring, payment data interception, and persistent implant deployment. In environments where PCI DSS compliance is expected, this class of vulnerability is not a marginal gap: it undermines the entire trust model. The fact that these devices were internet-facing amplifies the risk from a local physical attack to a remotely scalable one.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>The regulatory context: CRA and beyond<\/strong><\/li>\n<\/ul>\n\n\n\n<p class=\"has-text-align-left\">With the EU Cyber Resilience Act (CRA) entering its enforcement timeline, products with digital elements placed on the European market will be required to meet essential cybersecurity requirements throughout their lifecycle \u2014 including secure-by-default configuration, minimized attack surfaces, and vulnerability handling obligations. A device shipping with unauthenticated root access over both UART and Telnet would be a textbook non-compliance scenario. Manufacturers and importers should treat findings like these as a preview of what regulators will be looking for.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Key takeaways for practitioners<\/strong><\/li>\n<\/ul>\n\n\n\n<p class=\"has-text-align-left\">Never underestimate publicly available OSINT. The FCC database alone provided enough information to build a preliminary threat model, identify anti-tamper boundaries, and locate potential entry points \u2014 all before purchasing a single unit. For red teamers and security researchers, this is a reminder that passive reconnaissance on regulatory filings can dramatically accelerate hardware assessments. For manufacturers and blue teamers, it is a reminder that your FCC submissions, teardowns, and service manuals are part of your attack surface.<\/p>\n\n\n\n<div class=\"wp-block-uagb-advanced-heading uagb-block-bdaaed34\"><h2 class=\"uagb-heading-text\"><strong>WANNA BECOME A CERTIFIED HARDWARE HACKER?<\/strong><\/h2><\/div>\n\n\n\n<p class=\"has-text-align-center\">The Offensive Hardware Hacking Training is a Self-Paced training including Videos, a printed Workbook and a cool Hardware Hacking Kit. And\u2026 you get everything shipped home Worldwide! For more info: <\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Offensive Hardware Hacking Training\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/zbUuBZJIHkE?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Some time ago I was shopping around the city when I stumbled on an interesting POS (Point Of Sale). While [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":741,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_uag_custom_page_level_css":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[20,16,22],"tags":[28,27,26,29],"class_list":["post-740","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-full-disclosure","category-general","category-hardware-hacking","tag-hardware-hacking","tag-hardware-security","tag-pos-hacking","tag-whidboard"],"uagb_featured_image_src":{"full":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/IMG_2242-ezgif.com-video-to-gif-converter.gif",800,1422,false],"thumbnail":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/IMG_2242-ezgif.com-video-to-gif-converter-150x150.gif",150,150,true],"medium":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/IMG_2242-ezgif.com-video-to-gif-converter-169x300.gif",169,300,true],"medium_large":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/IMG_2242-ezgif.com-video-to-gif-converter-768x1365.gif",768,1365,true],"large":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/IMG_2242-ezgif.com-video-to-gif-converter-576x1024.gif",576,1024,true],"1536x1536":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/IMG_2242-ezgif.com-video-to-gif-converter.gif",800,1422,false],"2048x2048":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/IMG_2242-ezgif.com-video-to-gif-converter.gif",800,1422,false],"woocommerce_thumbnail":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/IMG_2242-ezgif.com-video-to-gif-converter-300x300.gif",300,300,true],"woocommerce_single":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/IMG_2242-ezgif.com-video-to-gif-converter-600x1067.gif",600,1067,true],"woocommerce_gallery_thumbnail":["https:\/\/www.hardwaresecurity.it\/wp-content\/uploads\/2026\/04\/IMG_2242-ezgif.com-video-to-gif-converter-100x100.gif",100,100,true]},"uagb_author_info":{"display_name":"admin","author_link":"https:\/\/www.hardwaresecurity.it\/?author=1"},"uagb_comment_info":0,"uagb_excerpt":"Some time ago I was shopping around the city when I stumbled on an interesting POS (Point Of Sale). While [&hellip;]","_links":{"self":[{"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=\/wp\/v2\/posts\/740","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=740"}],"version-history":[{"count":3,"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=\/wp\/v2\/posts\/740\/revisions"}],"predecessor-version":[{"id":770,"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=\/wp\/v2\/posts\/740\/revisions\/770"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=\/wp\/v2\/media\/741"}],"wp:attachment":[{"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=740"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=740"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hardwaresecurity.it\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=740"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}