Researcher: bugs in Nexx's Wi-Fi-enabled garage door openers let hackers open garages; Nexx hasn't responded to patch appeals for months, including from the DHS
A security researcher found a series of vulnerabilities with the Nexx brand of smart garage openers. Tweets: @josephfcox Tweets: Joseph Cox / @josephfcox : New: hackers can remotely open smart garage doors across the world, over the internet. The issues are live right now. Researcher warned vendor for months; I spent weeks. The company is just ignoring, so researcher publishing. DHS published an alert https://www.vice.com/...
Context & Ripple Effects
The Nexx disclosure lands in a long line of cheap consumer-IOT failures documented over the past decade: researchers found 12 of 16 Bluetooth smart locks they tested could be hacked open back in 2016, and in 2020 found actively-exploited backdoors in low-cost Jetstream and Wavlink routers sold through mainstream retail. What distinguishes the Nexx case is not the flaw class but the response failure — months of silence from the vendor toward both the researcher and the DHS, which escalated by publishing its own public alert.
That escalation matters because it forces disclosure into the open: with no patch path, the researcher publishing exploit details converts a private remediation channel into live attack surface for every internet-connected Nexx opener worldwide.
First-order effects
- Owners of Nexx Wi-Fi garage openers face immediate risk that strangers can trigger their garage doors remotely over the internet, with no firmware fix available since Nexx has shipped nothing after months of appeals.
- Nexx now owns a public security reputation problem: the DHS alert plus the researcher's publication make the vulnerability discoverable to attackers at scale, while the company's non-response is itself the story.
Second-order effects
- Retail channels stocking Nexx hardware face pressure to justify carrying a product whose maker ignores federal patch requests — the same exposure that hit Walmart, Amazon, and eBay listings when router backdoors surfaced in related coverage.
- Competing smart-garage and smart-home vendors gain a marketing wedge around patch responsiveness, echoing how Philips Hue's quickly-patched bulb flaw became a contrast point against unresponsive vendors.
Third-order effects
- If vendors can ignore even DHS appeals without consequence, disclosure norms harden toward publish-anyway research and government alerts-as-pressure, shifting responsibility for consumer IoT safety from vendors onto researchers and agencies.
- The pattern points toward regulatory structure for consumer IoT — mandatory patch commitments or certification before sale — as repeated cases of silent vendors give regulators a concrete record of market failure.
The trend: Consumer IoT security is converging on a disclosure regime where government alerts substitute for vendor action when low-cost device makers won't patch.