An untrusted update is installed
An attacker replaces a firmware package before the gateway installs it. Transport protection alone does not establish who produced the package.
- Condition
- The gateway accepts a package without verifying a trusted signature and the intended product identity.
- Consequence
- Attacker-controlled firmware can change device behaviour and expose credentials.
- Proposed measure
- Verify the signature and package identity before installation, protect the trust anchor and reject disallowed rollback versions.