Live data from Hacker News

Tenda firmware (multiple versions) contains hidden authentication backdoor

kb.cert.org

111–120 of 136 posts

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#111

The article doesn't disclose the value of "sys.rzadmin.password", but this writeup from 2022 does: https://boschko.ca/tenda_ac1200_router/ Spoiler: it's "rzadmin". And it looks like there are a bunch of other goodies in the firmware, too.

Nearly 4 years from last notification and the password is the same; either thats real incompetence, or a hilarious power move

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#112

Oh this is amazing! I have a few of their cube routers sitting around and I always hated how app-locked their firmware was when it really is just a wifi repeater with a few extras (mesh) on top. Root access will do wonders to bypassing the app now (and also disabling their ping-for-green-light mechanism which spams the network with a constant dns resolution to microsoft.com lol). Also honest take this looks less like…

why would a consumer device need a randomized password?

Maybe so when you factory reset the device that it sets the admin to something you can maybe read off the label? At least that way the random attacker needs physical access to your space.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#113
post #49
post #46

Earlier quoted context omitted.

Pretty sure the point was to invert it. :)

Yes, I got their point. My point is that’s the opposite of reality.

The main reason I assumed you didn't is because you linked to Hanlon's Razor and explained it in a way that made it seem like you didn't think the other person knew.

I think it's true to some extent that a lot of the backdoors really are just stupidity, like debugging tools put into prod for convenience. Rather than suggesting that it is genuine malice, maybe the right thing to say is that for security, it doesn't matter whether or not it is malice for most purposes. If it did, it would give more incentive to do as much as possible to disguise malicious backdoors as mistakes.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#114

> The associated username is not validated, so any provided username will succeed when paired with the backdoor password. Great. I am really wondering why should the customers trust these manufacturers. At this point I would not use any router with vendor-provided black box firmware. Full stop. I would always install OpenWRT or something similar on it before using it. And if that is not possible for whatever reason,…

Hm, do you ever go over 1gbit? If my understanding is correct, good affordable routers like Mikrotik's CCR2004 are fully closed, so the only option is to build your own shitty box which will be much less energy efficient than their specialized switch chips.

Pfsense or OPNsense can handle ~5 gbps routing/firewall on a low power AMD or Intel embedded chip. My now old Pfsense box I got off Aliexpress can comfortably handle 2.5 gbps on an ancient Celeron J4125 running around 10W total. 10+ gbps is feasible on a reasonable power budget with higher end hardware, though it starts to get more expensive.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#115

Earlier quoted context omitted.

At that point it’s not even a back door it’s just stupid default root password kind of design which used to be standard in this kind of hardware. Backdoor would at least try to be subtle :)

Backdoors are often (almost always?) designed to look like incompetence so that there's plausible deniability.

It's refreshing to see someone around here addressing the compulsively overlooked elephant in the room; plausible deniability. I am not implying it applies directly here, but notice the trend -- it's taboo to even speculate on and often gets rebuke for even hinting at it. The social convention around it is perfect cover. And I am not the only one that knows this. If we were to wake suddenly and realize the scale of relevance here, we'd probably all go full luddite. Call me paranoid though.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#116
post #115

Earlier quoted context omitted.

Backdoors are often (almost always?) designed to look like incompetence so that there's plausible deniability.

It's refreshing to see someone around here addressing the compulsively overlooked elephant in the room; plausible deniability. I am not implying it applies directly here, but notice the trend -- it's taboo to even speculate on and often gets rebuke for even hinting at it. The social convention around it is perfect cover. And I am not the only one that knows this. If we were to wake suddenly and realize the scale of r…

If this wasn’t Tenda maybe I would be more inclined to agree with you. We are talking about an extremely shitty bargain basement vendor. The three stars on Amazon kind of router company.

I think sufficiently explained by incompetence over malice applies here. Some nefarious three letter agency having a backdoor like this is pretty pointless anyway.

Unless you’ve enabled remote management you can’t even get to this backdoor from a physical network perspective.

And then you change some router settings which really aren’t a magical access point into your devices in your home. My PC isn’t just going to magically allow you to browse the file system just because a malicious actor got on my local network. They can’t intercept anything moving over TLS.

Not saying it’s good to have that kind of access, but I think at the scale of “typical home network of consumer devices” the utility and blast radius is pretty limited. Go ahead and launch a DDOS attack on my printer and use up my ink cartridges, I guess.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#117

Earlier quoted context omitted.

That backdoor is so up front about it. We might as well call it a frontdoor.

I mean, it's 99% sure this was supposed to be a debug feature...

Whatever these happen it's 50/50 either an internal debugging feature used when designing the device or intended as a way for customer support to more easily help people.

I remember when a backdoor was discovered in the most popular brand of keylogging devices[0], likely added there in case someone forgot their password and reached out to support.

[0] https://old.reddit.com/r/cybersecurity/comments/jw6k5v/backd...

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#118

Earlier quoted context omitted.

I mean, it's 99% sure this was supposed to be a debug feature...

Whatever these happen it's 50/50 either an internal debugging feature used when designing the device or intended as a way for customer support to more easily help people. I remember when a backdoor was discovered in the most popular brand of keylogging devices[0], likely added there in case someone forgot their password and reached out to support. [0] https://old.reddit.com/r/cybersecurity/comments/jw6k5v/backd...

> a way for customer support to more easily help people

This is my guess. People don't like it when a device they have turns into a brick of e-waste because they can't remember their password. So most consumer devices have either a "reset to defaults" feature or a hidden support password. Even enterprise routers and switches often have this.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#119
post #115

Earlier quoted context omitted.

It's refreshing to see someone around here addressing the compulsively overlooked elephant in the room; plausible deniability. I am not implying it applies directly here, but notice the trend -- it's taboo to even speculate on and often gets rebuke for even hinting at it. The social convention around it is perfect cover. And I am not the only one that knows this. If we were to wake suddenly and realize the scale of r…

If this wasn’t Tenda maybe I would be more inclined to agree with you. We are talking about an extremely shitty bargain basement vendor. The three stars on Amazon kind of router company. I think sufficiently explained by incompetence over malice applies here. Some nefarious three letter agency having a backdoor like this is pretty pointless anyway. Unless you’ve enabled remote management you can’t even get to this ba…

Well, as mentioned (but perhaps not with sufficient emphasis), I wasn’t implying that this case is necessarily some 3-letter agency op. However, things eg(*) CopyFail, XZ Utils / Jia Tan, Intel ME/IME, Heartbleed, Dirty COW, CVE‑2021‑3156, third‑party contractors, supply chains, and the myriad opportunities all around, are but a few examples that leave me cynical. I don’t claim detailed, expert understanding for any of these; however, I’m convinced the majority of such things remain unknown, and a that our perceived malice:incompetence ratio is off.

I think we could stop reflexively defaulting to “incompetence” when the end result just as easily resembles a deliberate exploit. Plausible deniability is an extremely effective cover when it’s smartly applied.

I’m not disputing any of your specific technical points; my cynicism is thematic. Even when I try to muzzle it, it tends to get through. The parent comment, though short, is dense with implications about cheap gear, opaque firmware, exposure surfaces I think deserve more sustained attention.

* A quick, generic, maybe sub-ideal list to harden my point.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#120
post #78

Earlier quoted context omitted.

How? Neither their comment nor mine have anything malicious in their tone nor content.

Unfortunately, explaining a joke won’t make it funny afterward I guess.

As someone who really doesn’t take themselves even the slightest bit seriously, if there was ever a chance that your comment was funny then I would have realised it was a joke. ;)
Post reply on HN