Live data from Hacker News

Arris / Arris-variant DSL/Fiber router critical vulnerability exposure

derekabdine.com

21–30 of 36 posts

Re: Arris / Arris-variant DSL/Fiber router critical vulnerability exposure

#21
post #18

I read this and _instantly_ wonder if it's viable for certificate extraction to bypass the god-awful NAT system in AT&T's equipment, a-la pfatt: https://github.com/MonkWho/pfatt Edit: Ah yes, this is covered in the section "Obtaining the certificate via reboot & exploitation" Sadly my hardware appears to be patched.

You can downgrade the firmware and extract the certs: https://www.dupuis.xyz/bgw210-700-root-and-certs/ However, AT&T added another layer of authentication in mid-2021 that precludes the use of third-party hardware. I don't think that part has been cracked yet.

You don't need the 802.1x certificate, it's never actually been needed: https://www.dslreports.com/forum/r33442912-AT-T-Fiber-Bye-by...

Re: Arris / Arris-variant DSL/Fiber router critical vulnerability exposure

#22

For Frontier / Ziply users using an NVG448 - it's also affected.

This modem is the last released DSL modem that Ziply seems to be supporting :c

I wish Ziply would officially support more modern DSL modems like the hardware that is in the C4000BG, that modem is able to make marginal DSL circuits perform so much better.

Re: Arris / Arris-variant DSL/Fiber router critical vulnerability exposure

#23
post #13

Earlier quoted context omitted.

You can make up whatever fallacious slippery slope arguments you care to invent, but such routers already exist and they are the best, most secure routers you can buy.

May I ask what are those routers?

A Cisco 8200 would probably be what he wants.

Re: Arris / Arris-variant DSL/Fiber router critical vulnerability exposure

#24
post #13

Earlier quoted context omitted.

You can make up whatever fallacious slippery slope arguments you care to invent, but such routers already exist and they are the best, most secure routers you can buy.

May I ask what are those routers?

He's probably talking about Nest, Eero, AirPort (RIP), etc.

Re: Arris / Arris-variant DSL/Fiber router critical vulnerability exposure

#27
How do companies like Arris keep getting work?

I have an ISP supplied Arris Cable Modem (luckily not vulnerable) and it is dreadful. The UI is shonky, looking at the HTML & CSS underlying it is enough to make you weep, outdated JS libraries, and - seemingly - no software updates.

I could just about understand if it was stable and gave good WiFi - but the ISP's forums are full of people complaining about it.

All I can assume is that Arris is £1 cheaper than the next model, and the ISP have decided that dealing with customer complaints is cheaper than a higher CapEx.

Re: Arris / Arris-variant DSL/Fiber router critical vulnerability exposure

#28

Test Typedream comment

Pardon me for ignoring the implied "please ignore", but I'm very curious what "typedream" refers to? The only references I can find online are to a website builder platform, but the name sounds like it could represent a client app or maybe even a keyboard?

Re: Arris / Arris-variant DSL/Fiber router critical vulnerability exposure

#29
post #28

Test Typedream comment

Pardon me for ignoring the implied "please ignore", but I'm very curious what "typedream" refers to? The only references I can find online are to a website builder platform, but the name sounds like it could represent a client app or maybe even a keyboard?

Hey there,

Yes please ignore the comment!

Also, yes, it's a website builder! this comment was to test a notification tool that I'm using right now to notify whenever a new mention of "Typedream" shows up on HackerNews!

Re: Arris / Arris-variant DSL/Fiber router critical vulnerability exposure

#30
post #3

> It is possible to recover the WiFi access code and SSID, remote administration password, SIP credentials (if VoIP is supported), ISP CWMP/TR-069 endpoint URLs and their username and password as well as other sensitive information, although some parts may require more complicated techniques or computing resources that may not be available to all attackers. Network-based unauthenticated exploitation is most severe if…

Since you've operated both, whats your opinion on the Ubiquiti vs the TP-Link Omada and why did you switch?

I've done something similar with a Mikrotik CRS-309 as a router and some Ubiquiti U6 Meshes. The fiber ISP here leaves it to the owner to buy their own hardware to connect to a Icotera in bridge mode. I believe it allows the ISP to reduce their operating costs since theres no need to support a complex all in one router / switch / AP. Anything beyond the bridge is the users responsibility.

Post reply on HN