Tenda firmware (multiple versions) contains hidden authentication backdoor
11–20 of 136 posts
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#12https://boschko.ca/tenda_ac1200_router/
Spoiler: it's "rzadmin". And it looks like there are a bunch of other goodies in the firmware, too.
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#13Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#14[flagged]
If you're accusing CERT of hypocrisy, what's an example of the second case?
Barracuda Networks: https://krebsonsecurity.com/2013/01/backdoors-found-in-barra...
Fortinet: https://community.spiceworks.com/t/hard-coded-password-backd...
Korenix: https://sec-consult.com/vulnerability-lab/advisory/backdoor-...
The fact that the password is "rzadmin" makes it a lot more likely that this is just run of the mill stupidity, and not something more nefarious: you'd want a backdoor that isn't blindingly obvious and usable by the CIA.
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#15I have a free give-away mikrotik unit in the same price bracket (literally free: they were both conference give-aways) it's physically smaller and it runs what appears to be their mainline code. Say what you like about microtik for quality, they provide pretty much every knob and frob you could want.
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#16Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#17Have used their travel wifi product back when hotel wifi was a strange beast. Wouldn't expect to need it now eSIM and ubiquitous internet travel pricing means the hotel wifi may be the LEAST valid path to access things. I have a free give-away mikrotik unit in the same price bracket (literally free: they were both conference give-aways) it's physically smaller and it runs what appears to be their mainline code. Say w…
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#18The US/Israel would never do such a thing, buy UniFi/Fortinet/Palo Alto!
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#19The article doesn't disclose the value of "sys.rzadmin.password", but this writeup from 2022 does: https://boschko.ca/tenda_ac1200_router/ Spoiler: it's "rzadmin". And it looks like there are a bunch of other goodies in the firmware, too.
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#20Have used their travel wifi product back when hotel wifi was a strange beast. Wouldn't expect to need it now eSIM and ubiquitous internet travel pricing means the hotel wifi may be the LEAST valid path to access things. I have a free give-away mikrotik unit in the same price bracket (literally free: they were both conference give-aways) it's physically smaller and it runs what appears to be their mainline code. Say w…
I’m working on a hotel right now. And I’ve gone to great lengths to make the wifi more secure. Everyone on their own VLAN. Separate PPSK for each room. Credentials are randomly generated and not some ridiculous pattern of last name and room number or similar. We built our own custom access control system, with what at the time was the strongest keycards we could find (mifare desfire ev3), I’m really trying to make a…
Gets hard when you bring "smart" TV's to the table. They're going to need to expose into this system somewhat 'credential-free' but if you do it off MAC address then a determined user could disconnect, find MAC, clone ...