Longwatch devices are specialized components of Industrial Control Systems (ICS), frequently used in critical infrastructure sectors, including manufacturing, energy, and public utilities. Their function is often tied to the monitoring and management of physical processes, making their reliability and security fundamental to operational integrity and safety.
This vulnerability represents a critical risk due to the combination of unauthenticated remote access and execution at the SYSTEM level. An attacker does not require any prior access or credentials to gain full compromise of the device. Considering that these systems are often assumed to be isolated but can be inadvertently exposed to corporate networks or the Internet, the potential attack surface is significant.
The public availability of an exploit for this vulnerability is confirmed. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued advisories regarding vulnerabilities in Industrial Control Systems. This indicates that the vulnerability is well-understood and likely already being actively exploited by malicious actors. Any unpatched Longwatch device accessible from the network must be considered at imminent risk of compromise.
| Product | Longwatch |
| Date | 2025-12-04 12:21:38 |
Technical Summary
The origin of the vulnerability is CWE-306: Missing Authentication for Critical Function on a specific HTTP endpoint. The device’s web server exposes a powerful administrative function without requiring any authentication, allowing any user connected to the network to invoke it. The issue is compounded by the lack of integrity checks on the code or commands executed.
The attack chain is as follows:
- The attacker identifies a vulnerable Longwatch device accessible on the network.
- The attacker creates a simple HTTP GET request to a specific exposed endpoint (e.g.,
/api/debug/executeSystemCommand). - The request includes parameters that specify a command to be executed on the underlying operating system.
- The device firmware receives this request and, without validating any user session or credentials, passes the command directly to a system shell for execution with maximum privileges (SYSTEM/root).
A conceptual representation of the vulnerable logic is:
func handle_request(http_request):
// No authentication check is performed here
command = http_request.get_parameter("command")
// The user-supplied 'command' is executed directly
execute_as_system(command)
Affected versions: all Longwatch firmware versions prior to 5.2.1 are vulnerable.
Fixed version: the vulnerability was resolved starting with firmware version 5.2.1.
A successful exploit grants the attacker full control over the device, allowing them to disrupt industrial processes, exfiltrate sensitive operational data, move laterally to other devices on the ICS network, or potentially generate unsafe physical conditions.
Recommendations
- Update immediately: Upgrade all Longwatch devices to firmware version 5.2.1 or newer. This is the only way to fully mitigate the vulnerability.
- Mitigations: If an update is not immediately possible:
- Isolate Longwatch devices from the Internet and all non-essential corporate networks. These devices must not be reachable from untrusted networks.
- Implement network segmentation to limit communication to and from the devices exclusively to authorized systems present in the OT/ICS network.
- If the device must remain accessible, place it behind a Web Application Firewall (WAF) or a reverse proxy with rules that block access to the vulnerable HTTP endpoint.
- Search and Monitoring:
- Audit the web server logs of Longwatch devices for GET requests to unexpected or undocumented administrative endpoints, particularly those containing shell commands or suspicious strings.
- Monitor for any anomalous outbound network traffic from Longwatch devices, which could indicate a post-compromise C2 channel.
- Verify device integrity for any unauthorized configuration changes or the presence of new unknown files or processes.
- Incident Response:
- In case of suspected compromise, activate the incident response plan immediately. Isolate compromised devices from the network to prevent lateral movement and preserve forensic evidence.
- Defense in Depth:
- Ensure the availability of robust and tested backups of device configurations and process data for full recovery.
- Apply least privilege principles throughout the ICS network to limit the impact of a potential compromise.
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
