>> All posts

Exposed Nexus smart-meter logins and password spraying

The short version: A Nexus smart-meter web login exposed to the internet lets attackers quietly spray common and already-breached passwords at the device until one works — no exploit required, just an exposed login and one weak credential.

What you need to know

There's no CVE here and nothing to patch. The weakness is the combination of exposure and weak authentication: an internet-facing metering device with a web login, often protected by a default or simple password that was never changed.

Password spraying is the technique that turns that combination into access. Rather than guess many passwords against one account (which trips lockouts), the attacker tries a few high-probability passwords — including vendor defaults — slowly and quietly. IoT and metering devices are prime targets because they're rarely built or configured with strong authentication in mind.

  • How they find it — internet-wide scanning and web crawling readily surface exposed Nexus meter login panels.
  • How they use it — automated spraying with common, default, and previously-breached passwords, staying under any lockout thresholds.
  • What it leads to — access to the device's readings and configuration, a window into operational data, and a foothold on a device that should never have been internet-reachable in the first place.

How serious we see it

Low — by default, and worth taking seriously because of where it sits. A metering device exposed to the internet is a class of asset that usually shouldn't be reachable at all; the exposure itself is the finding. Weak or default credentials make it worse, turning a stray device into an easy win for an attacker. The reassuring part is that it's entirely in your hands to fix — change the credentials and, better still, get the device off the public internet — with no vendor patch required.

What to do

  • Get metering devices off the public internet — restrict access to trusted networks or a VPN; IoT and OT devices should not be internet-reachable.
  • Change default and weak passwords — enforce strong, unique credentials on every device account.
  • Restrict access to trusted IP addresses — limit who can even reach the login.
  • Limit and monitor failed authentication — where the device supports it, rate-limit attempts and watch for spraying.
  • Confirm your exposure first — verify whether any Nexus meter login is reachable from the internet at all.

How BreachRisk sees it

BreachRisk discovers exposed Nexus smart-meter login panels the way an attacker would — by crawling your external footprint — and then, where authorized, goes a step further than a scanner: it safely attempts a bounded, rate-limited authentication check using common, default, and exposed (breach-corpus) credentials, within strict non-disruptive limits rather than a brute-force flood. That's the honest difference between detecting a login and demonstrating whether it actually holds. "We have a metering device on the internet" becomes a straight answer: is it defended, or one default password away from access?

References

See your cyber risk, proven.