Earlier quoted context omitted.
Looking to do this to get off stock isp leased router. What's your hardware/distro rec?
Ryzen 5 with a dual 10Gbps NIC, running Debian. Overkill for a router/firewall, but I run other services on the same hardware including an email stack, Podman containers, and small AI model for use within Home Assistant. I wouldn't buy new hardware. Any modest machine built in the last decade would do. If possible, get a machine with an internal ATX power supply rather than an external brick, they tend to be more rel…
Tenda firmware (multiple versions) contains hidden authentication backdoor
51–60 of 136 posts
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#52> Tenda is a supplier of home and business network devices such as routers, switches, wireless access points, and video surveillance equipment. I was unfamiliar with Tenda. > Shenzhen Tenda Technology Co.,Ltd. ( https://www.tendacn.com/us/profile ) Tenda may just rebrand, right? It seems like many chinese brands will either rebrand or have a 'competing' brand with the same internals but different externals. (I have n…
Tenda has been around for quite a few years now. I don't imagine they'll rebrand. I have an ethernet over power adapter somewhere in a cupboard from perhaps 10 years ago. Back then it was standard for the admin password to be 'admin'. They'd often even print it on the device itself.
Yes but aren't you supposed to change that one? The problem with the rzadmin is that it will continue to work even after you change the regular admin one...
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#53And it’s always amateur hour backdoors somehow. If it was something sophisticated they might get a pass on „ok some security agency made them do it probably“
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#54Earlier quoted context omitted.
I’m working on a hotel right now. And I’ve gone to great lengths to make the wifi more secure. Everyone on their own VLAN. Separate PPSK for each room. Credentials are randomly generated and not some ridiculous pattern of last name and room number or similar. We built our own custom access control system, with what at the time was the strongest keycards we could find (mifare desfire ev3), I’m really trying to make a…
As long as I can bind more than one device in my room, and as long as I can "see" the devices amongst themselves, I'd love this. I can imagine people who want inter-room access but they can live through proxies offsite. If I want to do in room sharing, I need in room wifi. Gets hard when you bring "smart" TV's to the table. They're going to need to expose into this system somewhat 'credential-free' but if you do it o…
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#55Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#56The consistency with which networking hardware companies produce such garbage is crazy. And it’s always amateur hour backdoors somehow. If it was something sophisticated they might get a pass on „ok some security agency made them do it probably“
Or the amateur hour backdoors are there to be found.
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#57The article doesn't disclose the value of "sys.rzadmin.password", but this writeup from 2022 does: https://boschko.ca/tenda_ac1200_router/ Spoiler: it's "rzadmin". And it looks like there are a bunch of other goodies in the firmware, too.
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#58Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#59> Tenda is a supplier of home and business network devices such as routers, switches, wireless access points, and video surveillance equipment. I was unfamiliar with Tenda. > Shenzhen Tenda Technology Co.,Ltd. ( https://www.tendacn.com/us/profile ) Tenda may just rebrand, right? It seems like many chinese brands will either rebrand or have a 'competing' brand with the same internals but different externals. (I have n…
Tenda has been around for quite a few years now. I don't imagine they'll rebrand. I have an ethernet over power adapter somewhere in a cupboard from perhaps 10 years ago. Back then it was standard for the admin password to be 'admin'. They'd often even print it on the device itself.
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#60Great. I am really wondering why should the customers trust these manufacturers.
At this point I would not use any router with vendor-provided black box firmware. Full stop.
I would always install OpenWRT or something similar on it before using it.
And if that is not possible for whatever reason, I would not even think about buying such a device.