“A malicious attacker on the same network as the victim could fully compromise the target device without any user-interaction.”

The SuperNote Nomad runs an unauthenticated file server that lets anyone on the same network plant a firmware update. The firmware is signed with public debug keys, so a fake image passes. The rootkit installs on the next update. Ratta took over two months to respond.