I read this and _instantly_ wonder if it's viable for certificate extraction to bypass the god-awful NAT system in AT&T's equipment, a-la pfatt: https://github.com/MonkWho/pfatt Edit: Ah yes, this is covered in the section "Obtaining the certificate via reboot & exploitation" Sadly my hardware appears to be patched.
You can downgrade the firmware and extract the certs: https://www.dupuis.xyz/bgw210-700-root-and-certs/ However, AT&T added another layer of authentication in mid-2021 that precludes the use of third-party hardware. I don't think that part has been cracked yet.
Arris / Arris-variant DSL/Fiber router critical vulnerability exposure
21–30 of 36 posts
Re: Arris / Arris-variant DSL/Fiber router critical vulnerability exposure
#22For Frontier / Ziply users using an NVG448 - it's also affected.
I wish Ziply would officially support more modern DSL modems like the hardware that is in the C4000BG, that modem is able to make marginal DSL circuits perform so much better.
Re: Arris / Arris-variant DSL/Fiber router critical vulnerability exposure
#23Re: Arris / Arris-variant DSL/Fiber router critical vulnerability exposure
#24Earlier quoted context omitted.
You can make up whatever fallacious slippery slope arguments you care to invent, but such routers already exist and they are the best, most secure routers you can buy.
May I ask what are those routers?
Re: Arris / Arris-variant DSL/Fiber router critical vulnerability exposure
#25Re: Arris / Arris-variant DSL/Fiber router critical vulnerability exposure
#26Re: Arris / Arris-variant DSL/Fiber router critical vulnerability exposure
#27I have an ISP supplied Arris Cable Modem (luckily not vulnerable) and it is dreadful. The UI is shonky, looking at the HTML & CSS underlying it is enough to make you weep, outdated JS libraries, and - seemingly - no software updates.
I could just about understand if it was stable and gave good WiFi - but the ISP's forums are full of people complaining about it.
All I can assume is that Arris is £1 cheaper than the next model, and the ISP have decided that dealing with customer complaints is cheaper than a higher CapEx.
Re: Arris / Arris-variant DSL/Fiber router critical vulnerability exposure
#28Test Typedream comment
Re: Arris / Arris-variant DSL/Fiber router critical vulnerability exposure
#29Test Typedream comment
Pardon me for ignoring the implied "please ignore", but I'm very curious what "typedream" refers to? The only references I can find online are to a website builder platform, but the name sounds like it could represent a client app or maybe even a keyboard?
Yes please ignore the comment!
Also, yes, it's a website builder! this comment was to test a notification tool that I'm using right now to notify whenever a new mention of "Typedream" shows up on HackerNews!
Re: Arris / Arris-variant DSL/Fiber router critical vulnerability exposure
#30> It is possible to recover the WiFi access code and SSID, remote administration password, SIP credentials (if VoIP is supported), ISP CWMP/TR-069 endpoint URLs and their username and password as well as other sensitive information, although some parts may require more complicated techniques or computing resources that may not be available to all attackers. Network-based unauthenticated exploitation is most severe if…
I've done something similar with a Mikrotik CRS-309 as a router and some Ubiquiti U6 Meshes. The fiber ISP here leaves it to the owner to buy their own hardware to connect to a Icotera in bridge mode. I believe it allows the ISP to reduce their operating costs since theres no need to support a complex all in one router / switch / AP. Anything beyond the bridge is the users responsibility.