Live data from Hacker News

Unauthenticated RCE in Motorola's MR2600 Router

mrbruh.com

21–30 of 32 posts

Re: Unauthenticated RCE in Motorola's MR2600 Router

#22
post #15

Earlier quoted context omitted.

An allegory here would be someone stealing an easily stealable car (e.g. doing the Kia Challenge) and causing damage or injury. The thief would be liable, not the owner

Generally any damage done by a car is the responsibility of its owner. The owner will likely be sued anyway, because they have insurance and assets, and the thief (even if known) does not.

> The majority common law rule among the 50 states is that the owner of a stolen vehicle will not be held liable for damages when the vehicle is stolen and then involved in an accident that causes injury or property damage. This is because the vehicle was taken without the consent of the owner, who did not cause the accident.

https://www.mwl-law.com/wp-content/uploads/2018/02/OWNER-LIA...

Re: Unauthenticated RCE in Motorola's MR2600 Router

#23
post #10

Vendor wise, these were never really made by a “Motorola” -this is a Zoom router (thus the domain) that used the Motorola name under license. The “old” Motorola router division Motorola Home got sold to Arris _without_ the brand name in 2013, and then the brand name went to Zoom in 2016. Zoom merged with another vendor called Minim, went bankrupt in 2023, and the assets were bought by a company called e2Companies in…

[dead]

Re: Unauthenticated RCE in Motorola's MR2600 Router

#24
post #16
post #14

Earlier quoted context omitted.

But if it’s the isp delivered router they should carry the responsibility

I would assume that liability is avoided when someone has done a reasonable effort to secure the device. The user needs to make sure they've secured their router from unauthorized access by using proper passwords. The ISP needs to make sure the router is delivered with the latest firmware and is pre-configured to be secure.

I would not assume that.

Because British government has just made leaseholders of apartments liable for costs of fixing forged and fraudulently obtained fire safety certification of apartment blocks.

The manufacturers of cladding materials have forged the fire safety certificate, the construction company has not followed the law when it comes to fire breaks and other fire safety system, the government building control has examined the building and signed it off as correct, possibly corruptly.

But after a skyscraper burned down with all the residents inside, now the residents are liable.

Re: Unauthenticated RCE in Motorola's MR2600 Router

#25

In Germany we have "Störerhaftung" where routerowners are responsible for everything that happens through their router. I wonder how this would hold up in court, couldn't you argue that routers are generally buggy, how can they force any responsibility if they can easily be hacked?

[dead]

Re: Unauthenticated RCE in Motorola's MR2600 Router

#26

>42 hosts with remote management >vender doesn’t want to fix it Sometimes I wonder if the white hat hackers who find such a thing should just take it a step further and patch those hosts. Take the firmware, fix those bugs and update those 42 routers.

Just flash OpenWRT to them? :) (a script could prepare a matching default config)

The MR2600 is a rebranded (or same ODM) D Link DIR-882 with a different plastic case, but the MR doesn't come with a rear USB 2.0 port. The FCC photos for each are identical otherwise, right down to the silkscreened board revision.

There's already an OpenWRT image for the DLink model, so coming up with an entry for the Motorola version shouldn't be hard.

Re: Unauthenticated RCE in Motorola's MR2600 Router

#27

>42 hosts with remote management >vender doesn’t want to fix it Sometimes I wonder if the white hat hackers who find such a thing should just take it a step further and patch those hosts. Take the firmware, fix those bugs and update those 42 routers.

Probably simpler to brick them, forcing the owners to upgrade to a modern and supported device.

Or upgrade them to modern OpenWrt, which has supported the near identical (minus USB port) D-Link DIR-882 since 2021: https://openwrt.org/toh/d-link/dir-882_a1 , as User 6SixTy has hinted at.

Re: Unauthenticated RCE in Motorola's MR2600 Router

#28
post #11

Really curious the use of the "zoom.com" domain. However, since the endpoint uses insecure HTTP, maybe this should be a simple endpoint/hostname redirection. A search of "router/firmware/query.aspx" leads me to D-Link endpoints who also uses the "wrpd" subdomain.

... Because it is a D-Link DIR-882 in a different box: https://openwrt.org/toh/d-link/dir-882_a1

Re: Unauthenticated RCE in Motorola's MR2600 Router

#29

Earlier quoted context omitted.

Probably simpler to brick them, forcing the owners to upgrade to a modern and supported device.

Or upgrade them to modern OpenWrt, which has supported the near identical (minus USB port) D-Link DIR-882 since 2021: https://openwrt.org/toh/d-link/dir-882_a1 , as User 6SixTy has hinted at.

I actually have put that firmware on a MR2600, and it boots, not so sure about working well though. Screwing with OpenWRT and a vague sense it has a twin were my only memories of it. I had to retrace my own research from 4 years ago to come up with something worthy of a comment.

Re: Unauthenticated RCE in Motorola's MR2600 Router

#30
post #16

Earlier quoted context omitted.

I would assume that liability is avoided when someone has done a reasonable effort to secure the device. The user needs to make sure they've secured their router from unauthorized access by using proper passwords. The ISP needs to make sure the router is delivered with the latest firmware and is pre-configured to be secure.

I would not assume that. Because British government has just made leaseholders of apartments liable for costs of fixing forged and fraudulently obtained fire safety certification of apartment blocks. The manufacturers of cladding materials have forged the fire safety certificate, the construction company has not followed the law when it comes to fire breaks and other fire safety system, the government building contro…

This is ultimately a failing of democracy itself. This stuff was legal, and it's hard to make a law that reaches back decades to impose costs on manufacturers or real estate developers without drastic economic side effects. Leaseholders in theory were one of the beneficiaries of the cheap building techniques, but a lot (maybe most?) of the burden of remediation has actually fallen to the taxpayer - typical politicians, winning votes in the 1980s and paying the tax in the 2020s.

Known unsafe building methods should not have been legal, but we know that politicians have been avoiding legislating this specific issue for more 50 years[1]. Politicians need votes or kickbacks in months or a few years at most. Fire safety is a long term investment against a rare problem. Long term investments against even common problems are basically impossible in modern democracies. For example, if you legislate cycle path networks everywhere people will eventually love them and fight to keep them, in addition to delivering economic and health benefits, but outside the Netherlands very few places do it - because it took 40 years in the Netherlands.

[1]

Post reply on HN