
Thousands of servers can be backdoored via buggy motherboard controllers
Thousands of Internet-connected servers sold by the world's biggest manufacturers can be remotely backdoored by exploiting critical vulnerabilities — some more than a decade old — buried deep inside system motherboards. That's according to research presented Wednesday at Black Hat 2026, in a talk titled "Lights Out: BMCs Are Still Broken and Now We Have the Receipts," with a companion presentation at DEF CON 34.
Baseboard management controllers (BMCs) are miniature computers embedded into the motherboards of virtually every enterprise server. They run their own firmware, network stack, and IP address, and keep working even when the server they're attached to is powered off or unresponsive — what's known as "out-of-band" management. That independence is exactly what makes BMCs an attractive target: per research from Lava, of 36,872 internet-exposed BMC interfaces running the IPMI protocol, 24,650 disclose a password-derived authentication hash before login — the result of an architectural flaw in the IPMI 2.0 spec itself (CVE-2013-4786) that allows offline password cracking without a single detectable login attempt. More than half of the vulnerable controllers were Supermicro, with HPE and Dell servers also affected.
“The BMC operates outside that trust boundary, giving an attacker control beneath the host while remaining largely invisible to protective tools.”
— Michael Katchinskiy, Head of Security Research at Lava
- 36,872 BMCs were found exposed to the internet; 24,650 (67%) leak a password hash
- 6,240 controllers accepted an empty username with a weak password; 2,340 used passwords found in public wordlists
- A factory-default Supermicro password can be cracked in about an hour with a GPU rig; an HPE iLO password in about 32 seconds
The problem already has real-world consequences: researchers found a ransom note on one compromised HPE iLO 4 controller demanding 0.3 bitcoin — meaning attackers aren't just proving the attack works, they're already monetizing access to server infrastructure through persistent firmware backdoors that survive even a full operating system reinstall.
None of this should be read as personalized investment advice.

Comments (0)
No comments yet — be the first!
Related news
Most read
Silicon Valley Workers Are Wearing Noise-Cancelling Masks to Dictate AI Prompts
223 views
Elon Musk Expands Access to X Money, the Payments Service Inside X
153 views
Strategy Didn't Buy Any Bitcoin Last Week — and Now Has a Plan to Sell It
46 views
Layer-2: How Blockchains Get Faster Without Touching the Base Chain
44 views
Silicon Valley's weird AI-dictation mask trend is the tip of a $22 billion voice AI boom
33 views
Crypto Cards That Never Take Your Keys
32 views
Crypto Market Drops 4-5% in a Day: What Volume and Traders Are Saying
31 views

