Over 25k Linksys routers vulnerable to sensitive information disclosure flaw
1–10 of 38 posts
Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw
#2Repeat offenders should be held accountable, standards should be enforced (like running point releases of OpenWRT, providing vendor skins as a package, thus the vendor doesn't have to deal with software updates).
Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw
#3Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw
#4Pity that the author didn't mention alternative firmwares as an option to fix the vulnerability. I recommend everyone with the affected device to go to https://openwrt.org/toh/start?dataflt%5BBrand*%7E%5D=Linksys and install the OpenWRT firmware, it's pretty easy.
Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw
#5Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw
#6This is not a problem if you are behind a CG-NAT. If you are not (that should be the default) then ask your ISP to put you behind one. If they don't offer that service, then it's time to shop around.
Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw
#7This is not a problem if you are behind a CG-NAT. If you are not (that should be the default) then ask your ISP to put you behind one. If they don't offer that service, then it's time to shop around.
Asking your ISP to cripple your connection like that is a horrible "solution", and usually isn't a change they're prepared to make by request. If you have the option of shopping around for ISPs, the one that doesn't do CG-NAT is usually the best choice.
Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw
#8Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw
#9Earlier quoted context omitted.
Asking your ISP to cripple your connection like that is a horrible "solution", and usually isn't a change they're prepared to make by request. If you have the option of shopping around for ISPs, the one that doesn't do CG-NAT is usually the best choice.
I disagree with you. The majority of users don't care about being behind a CG-NAT (what you call "crippling"), and CG-NAT offers a very big layer of protection that avoids problems like the one on this article.
Also it is very likely you are still vulnerable from other users on the same ISP attacking you.
Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw
#10Earlier quoted context omitted.
Asking your ISP to cripple your connection like that is a horrible "solution", and usually isn't a change they're prepared to make by request. If you have the option of shopping around for ISPs, the one that doesn't do CG-NAT is usually the best choice.
I disagree with you. The majority of users don't care about being behind a CG-NAT (what you call "crippling"), and CG-NAT offers a very big layer of protection that avoids problems like the one on this article.
Users don't explicitely care because they don't know. It doesn't make much difference when viewing YouTube videos, but there's more to the Internet than cat videos.