4 MIN READ
Picture the standard homelab Pi. A learning tool, a quick deployment, a way to test something on the cheap. Now move it into a production rack, behind the firewall, plugged into a switch, running a real workload on the same network as the payment system. The hardware has not changed. The risk has. No IPMI, no vendor firmware patching schedule, no coherent story about which firmware version is even running. Most production Pis in 2026 were deployed by a developer who needed a quick fix, were never documented, and have been running quietly in a corner of the rack ever since. That is the security incident.
What the actual problem is
Three problems, stacked. Inventory, patching, supply chain. None of them are unique to the Pi, but the Pi hits all three at once.
Inventory is the worst of them. Most organisations cannot answer the simple question of how many Pis they actually have, and where. The hardware is small, cheap, and easy to deploy. It does not show up in the standard endpoint management tooling. It does not run the corporate EDR. It does not appear in Active Directory. It lives in a grey zone between IT, OT, and the developer who plugged it in. The audit team walks the racks and finds five of them behind a monitor that no one is using.
Patching is the next one. There is no managed OS update path. apt get update and apt get upgrade work, but they require someone to log in and run them. Most production Pis have not been logged into in months.
The supply chain is the third. The Raspberry Pi Foundation has had firmware and bootloader issues over the years. The Pi 5 shipped with a known EEPROM bug in early 2024 that allowed unauthenticated boot configuration changes. The bug was patched upstream. Most Pis in production have not been updated.
The result is a fleet of unmanaged, unpatched devices sitting in the production network. An attacker who finds one has a foothold on hardware no one is monitoring, on firmware no one has touched, with access to whatever the network allows. The exfiltration pattern is the standard unmanaged IoT play: a quiet device on a quiet network, with a constant connection out. The Pi is a particularly good version of the play because it has real compute, real storage, and a Linux userspace the attacker can use as a beachhead.
What to actually do
Start with the inventory. Walk the racks. Look behind the servers. The Pis tend to cluster near the network gear, on top of a switch, or behind a monitor no one is using. The cases are distinctive. Count them, and put each one in a spreadsheet before doing anything else.
Next, network segmentation. Move the Pis off the production VLAN and onto a management network with explicit rules about what they can and cannot reach. The goal is to make sure that if one of them is compromised, the attacker is not also on the payment network.
Then decide which ones to replace. A small industrial PC will cost roughly five times the Pi, and the security improvement is roughly a hundred times. For most production Pis, the replacement is the right answer. The Pi in a homelab is fine. The Pi in a development environment is fine. The Pi in production is a liability.
If replacement is not an option, the next move is the bastion. Disable password auth. Disable root login. Force key based SSH. Lock down the firewall. Disable every service the Pi does not need. Then update the firmware, the OS, and the installed packages. Do this on a schedule. Audit it on a schedule. The Pi can be made reasonable. It cannot be made invisible. The audit has to happen, or none of the rest matters.

The bottom line
Inventory, segment, replace or bastion. The fix is operational, not technical. Walk the racks. Find the Pis. Move them off the production VLAN, or off the network entirely.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



