> Tenda is a supplier of home and business network devices such as routers, switches, wireless access points, and video surveillance equipment. I was unfamiliar with Tenda. > Shenzhen Tenda Technology Co.,Ltd. ( https://www.tendacn.com/us/profile ) Tenda may just rebrand, right? It seems like many chinese brands will either rebrand or have a 'competing' brand with the same internals but different externals. (I have n…
Tenda firmware (multiple versions) contains hidden authentication backdoor
81–90 of 136 posts
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#82Oh this is amazing! I have a few of their cube routers sitting around and I always hated how app-locked their firmware was when it really is just a wifi repeater with a few extras (mesh) on top. Root access will do wonders to bypassing the app now (and also disabling their ping-for-green-light mechanism which spams the network with a constant dns resolution to microsoft.com lol). Also honest take this looks less like…
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#83Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#84Oh this is amazing! I have a few of their cube routers sitting around and I always hated how app-locked their firmware was when it really is just a wifi repeater with a few extras (mesh) on top. Root access will do wonders to bypassing the app now (and also disabling their ping-for-green-light mechanism which spams the network with a constant dns resolution to microsoft.com lol). Also honest take this looks less like…
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#85Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#86Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#87The consistency with which networking hardware companies produce such garbage is crazy. And it’s always amateur hour backdoors somehow. If it was something sophisticated they might get a pass on „ok some security agency made them do it probably“
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#88Common situation for small-company software... Backdoor passwords left for convenient debugging are not surprising anymore.
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#89Earlier quoted context omitted.
I mean, it's 99% sure this was supposed to be a debug feature...
and "accidentally" they forgot to disable it when releasing
This being said makes the situation for an attacker awfully convenient...
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#90Earlier quoted context omitted.
That backdoor is so up front about it. We might as well call it a frontdoor.
I mean, it's 99% sure this was supposed to be a debug feature...
- What did you think was going on?
Jack Black: Oh, I thought it was an STO.
- STO?
Jack Black: Standard Training Op.