YX International left SMS database of one-time passcodes exposed online
- Organization
- YX International
- Exploit
- Misconfiguration
- Industry
- Telecommunications
TechCrunch reported on February 29, 2024 that YX International, an Asian company that manufactures cellular networking equipment and routes SMS traffic for mobile operators, had left one of its internal databases reachable from the internet without a password.
Anyone who knew the database's public IP address could open it in a web browser. Security researcher Anurag Sen found the system during a routine sweep for exposed cloud databases and passed the details to TechCrunch, which identified the owner and alerted the company.
The database logged the contents of text messages the company had routed, including one-time passcodes and password reset links sent on behalf of large online platforms. TechCrunch said messages destined for Facebook, WhatsApp, Google and TikTok users were among them. The logs went back to July 2023 and the database was still being written to when it was found. YX International says it handles about five million SMS messages a day.
The company took the database offline shortly after being contacted and a representative said it had sealed the vulnerability. YX International said the server kept no access logs, so it could not establish whether anyone else had reached the data, and it declined to say how long the system had been exposed. Forbes noted that the practical risk to individual accounts was limited because one-time codes expire quickly and would have to be used almost immediately.