Unauthenticated RCE in Motorola's MR2600 Router
1–10 of 32 posts
Re: Unauthenticated RCE in Motorola's MR2600 Router
#2>vender doesn’t want to fix it
Sometimes I wonder if the white hat hackers who find such a thing should just take it a step further and patch those hosts. Take the firmware, fix those bugs and update those 42 routers.
Re: Unauthenticated RCE in Motorola's MR2600 Router
#3>42 hosts with remote management >vender doesn’t want to fix it Sometimes I wonder if the white hat hackers who find such a thing should just take it a step further and patch those hosts. Take the firmware, fix those bugs and update those 42 routers.
Re: Unauthenticated RCE in Motorola's MR2600 Router
#4I wonder how this would hold up in court, couldn't you argue that routers are generally buggy, how can they force any responsibility if they can easily be hacked?
Re: Unauthenticated RCE in Motorola's MR2600 Router
#5In Germany we have "Störerhaftung" where routerowners are responsible for everything that happens through their router. I wonder how this would hold up in court, couldn't you argue that routers are generally buggy, how can they force any responsibility if they can easily be hacked?
Re: Unauthenticated RCE in Motorola's MR2600 Router
#6>42 hosts with remote management >vender doesn’t want to fix it Sometimes I wonder if the white hat hackers who find such a thing should just take it a step further and patch those hosts. Take the firmware, fix those bugs and update those 42 routers.
Re: Unauthenticated RCE in Motorola's MR2600 Router
#7>42 hosts with remote management >vender doesn’t want to fix it Sometimes I wonder if the white hat hackers who find such a thing should just take it a step further and patch those hosts. Take the firmware, fix those bugs and update those 42 routers.
But it’s definitely not white hat.
Re: Unauthenticated RCE in Motorola's MR2600 Router
#8>42 hosts with remote management >vender doesn’t want to fix it Sometimes I wonder if the white hat hackers who find such a thing should just take it a step further and patch those hosts. Take the firmware, fix those bugs and update those 42 routers.
Probably simpler to brick them, forcing the owners to upgrade to a modern and supported device.
Re: Unauthenticated RCE in Motorola's MR2600 Router
#9>42 hosts with remote management >vender doesn’t want to fix it Sometimes I wonder if the white hat hackers who find such a thing should just take it a step further and patch those hosts. Take the firmware, fix those bugs and update those 42 routers.
Re: Unauthenticated RCE in Motorola's MR2600 Router
#10The “old” Motorola router division Motorola Home got sold to Arris _without_ the brand name in 2013, and then the brand name went to Zoom in 2016. Zoom merged with another vendor called Minim, went bankrupt in 2023, and the assets were bought by a company called e2Companies in 2024.
So e2Companies is who the author should email, but good luck. I’m shocked these were even “maintained” until 2024.