ADVISORIES | July 19, 2017

Ninebot by Segway miniPRO Vulnerabilities

Ninebot Limited, which purchased Segway Inc. in 2015, sells a line of self-balancing motorized electric scooters used for transportation under 30km/h. Recently, issues regarding the safety of scooters have surfaced, primarily caused by poor manufacturing quality or a general lack of safety-centered design.

Using reverse engineering and protocol analysis, IOActive determined that the Ninebot by Segway miniPRO had several critical vulnerabilities which were wirelessly exploitable. These vulnerabilities could be used by an attacker to bypass safety systems designed by Ninebot.

Launch PDF