Live data from Hacker News

Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

badpackets.net

21–30 of 38 posts

Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

#21

Linksys just doesn't give a shit. At all. I specifically bought one of their top end routers to use it as a NAS with USB storage, only to discover that their best of the best router serves files over.....Samba 1.0. Even though Samba 2.0 has been available for over a decade and Samba 3.0 is common place now. Which means that Windows 10 doesn't allow you to actually browse it by default anymore, since it's a huge secur…

Yeah I wouldn't trust Linksys to do even what their core competency is ... securely. Let alone any NAS.

Sadly the only good home NAS solutions are build it your own (time, hassle) or pay for something more expensive from Synology.

Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

#22
It would be nice if there was a home commercial product that cut out all the remote access or even local access, reduced feature set (I don't need NAS on my router), allowed admin access via a physical port only and thus cut out a lot of the attack surface area....

It shouldn't even be hard for Linksys (granted with their history I wouldn't trust them) or someone to provide that option. With a reduced feature set and etc maybe updates would be easier too.

Granted when it comes to home commercial routing products it looks like it is all about a bazillion new features (at least the way they look on the box / shopping sites) ... not less.

Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

#23

Linksys just doesn't give a shit. At all. I specifically bought one of their top end routers to use it as a NAS with USB storage, only to discover that their best of the best router serves files over.....Samba 1.0. Even though Samba 2.0 has been available for over a decade and Samba 3.0 is common place now. Which means that Windows 10 doesn't allow you to actually browse it by default anymore, since it's a huge secur…

You bought a router to use as a NAS? I think that's your problem right there. How is this even voted to the top? Edit: Looks like I hit a nerve. God forbid anyone buy hardware for a purpose it was actually designed for.

It's actually common nowadays to have NAS-type features in routers now. My non-Linkysys router has SMB/FTP access as part of the stock firmware for USB attached storage.

Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

#24
post #22

It would be nice if there was a home commercial product that cut out all the remote access or even local access, reduced feature set (I don't need NAS on my router), allowed admin access via a physical port only and thus cut out a lot of the attack surface area.... It shouldn't even be hard for Linksys (granted with their history I wouldn't trust them) or someone to provide that option. With a reduced feature set and…

Ubiquiti Networks have their Unifi product line that sells to business but since they don't charge licence fees have become quite popular with keen home users.

There's regular firmware updates and the feature set is quite standard.

Though their routers and access points are separate: Eg: Their smallest router: https://www.ui.com/unifi-routing/usg/

Their cheap WiFi AP: https://www.ui.com/unifi/unifi-ap-ac-pro/

To configure the network you use their controller software, can be deployed on a raspberry pi but I just run it ad hoc on my laptop when I need to change some configuration.

Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

#25
post #24
post #22

It would be nice if there was a home commercial product that cut out all the remote access or even local access, reduced feature set (I don't need NAS on my router), allowed admin access via a physical port only and thus cut out a lot of the attack surface area.... It shouldn't even be hard for Linksys (granted with their history I wouldn't trust them) or someone to provide that option. With a reduced feature set and…

Ubiquiti Networks have their Unifi product line that sells to business but since they don't charge licence fees have become quite popular with keen home users. There's regular firmware updates and the feature set is quite standard. Though their routers and access points are separate: Eg: Their smallest router: https://www.ui.com/unifi-routing/usg/ Their cheap WiFi AP: https://www.ui.com/unifi/unifi-ap-ac-pro/ To conf…

I keep meaning to try them out, although I have a bit of trouble parsing their product lines / names at times ;)

Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

#26
post #3

Pity that the author didn't mention alternative firmwares as an option to fix the vulnerability. I recommend everyone with the affected device to go to https://openwrt.org/toh/start?dataflt%5BBrand*%7E%5D=Linksys and install the OpenWRT firmware, it's pretty easy.

+1 for OpenWRT

I've had a Linksys WRT1900AC since its release (specifically on the promise of OpenWRT support)

The device has gradually gotten better and better with each OpenWRT release. These days I get a blistering 60MB/s file transfers over Wi-Fi to my laptop. Even with newer, "faster" specced devices on the market, I really can't see any compelling reason to upgrade

Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

#27

Linksys just doesn't give a shit. At all. I specifically bought one of their top end routers to use it as a NAS with USB storage, only to discover that their best of the best router serves files over.....Samba 1.0. Even though Samba 2.0 has been available for over a decade and Samba 3.0 is common place now. Which means that Windows 10 doesn't allow you to actually browse it by default anymore, since it's a huge secur…

You bought a router to use as a NAS? I think that's your problem right there. How is this even voted to the top? Edit: Looks like I hit a nerve. God forbid anyone buy hardware for a purpose it was actually designed for.

You may be lucky enough to have avoided learning about the shitshow that is consumer grade "routers". They seem to constantly be trying to come up with stupid shit they can do. Many of the "high end" of the spectrum of garbage have things like OpenVPN servers and samba shares off the included USB port.

They are all hot garbage and should not be used.

Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

#29

Once again embedded device security is a joke. Firmware updates are provided for 2 years or less on devices that end up lingering, acting as the core of networks for 5 to 15 years. Repeat offenders should be held accountable, standards should be enforced (like running point releases of OpenWRT, providing vendor skins as a package, thus the vendor doesn't have to deal with software updates).

> Once again embedded device security is a joke.

Have you seen the state of salaries in the firmware dev industry?

That pretty much explains why firmware security is such a mess. You pay peanuts you get peanuts.

Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

#30
At least I thought that you could opt out of the remote management at least on some models. This is what this seems to indicate as well: https://community.linksys.com/t5/Wireless-Routers/EA8300-can... When remote admin is disabled the info leak does not occur as far as I can tell. Not sure if anyone can confirm that as well.
Post reply on HN