Unauthenticated RCE in Motorola's MR2600 Router
21–30 of 32 posts
Re: Unauthenticated RCE in Motorola's MR2600 Router
#22Earlier quoted context omitted.
An allegory here would be someone stealing an easily stealable car (e.g. doing the Kia Challenge) and causing damage or injury. The thief would be liable, not the owner
Generally any damage done by a car is the responsibility of its owner. The owner will likely be sued anyway, because they have insurance and assets, and the thief (even if known) does not.
https://www.mwl-law.com/wp-content/uploads/2018/02/OWNER-LIA...
Re: Unauthenticated RCE in Motorola's MR2600 Router
#23Vendor wise, these were never really made by a “Motorola” -this is a Zoom router (thus the domain) that used the Motorola name under license. The “old” Motorola router division Motorola Home got sold to Arris _without_ the brand name in 2013, and then the brand name went to Zoom in 2016. Zoom merged with another vendor called Minim, went bankrupt in 2023, and the assets were bought by a company called e2Companies in…
Re: Unauthenticated RCE in Motorola's MR2600 Router
#24Earlier quoted context omitted.
But if it’s the isp delivered router they should carry the responsibility
I would assume that liability is avoided when someone has done a reasonable effort to secure the device. The user needs to make sure they've secured their router from unauthorized access by using proper passwords. The ISP needs to make sure the router is delivered with the latest firmware and is pre-configured to be secure.
Because British government has just made leaseholders of apartments liable for costs of fixing forged and fraudulently obtained fire safety certification of apartment blocks.
The manufacturers of cladding materials have forged the fire safety certificate, the construction company has not followed the law when it comes to fire breaks and other fire safety system, the government building control has examined the building and signed it off as correct, possibly corruptly.
But after a skyscraper burned down with all the residents inside, now the residents are liable.
Re: Unauthenticated RCE in Motorola's MR2600 Router
#25In Germany we have "Störerhaftung" where routerowners are responsible for everything that happens through their router. I wonder how this would hold up in court, couldn't you argue that routers are generally buggy, how can they force any responsibility if they can easily be hacked?
Re: Unauthenticated RCE in Motorola's MR2600 Router
#26>42 hosts with remote management >vender doesn’t want to fix it Sometimes I wonder if the white hat hackers who find such a thing should just take it a step further and patch those hosts. Take the firmware, fix those bugs and update those 42 routers.
Just flash OpenWRT to them? :) (a script could prepare a matching default config)
There's already an OpenWRT image for the DLink model, so coming up with an entry for the Motorola version shouldn't be hard.
Re: Unauthenticated RCE in Motorola's MR2600 Router
#27>42 hosts with remote management >vender doesn’t want to fix it Sometimes I wonder if the white hat hackers who find such a thing should just take it a step further and patch those hosts. Take the firmware, fix those bugs and update those 42 routers.
Probably simpler to brick them, forcing the owners to upgrade to a modern and supported device.
Re: Unauthenticated RCE in Motorola's MR2600 Router
#28Really curious the use of the "zoom.com" domain. However, since the endpoint uses insecure HTTP, maybe this should be a simple endpoint/hostname redirection. A search of "router/firmware/query.aspx" leads me to D-Link endpoints who also uses the "wrpd" subdomain.
Re: Unauthenticated RCE in Motorola's MR2600 Router
#29Earlier quoted context omitted.
Probably simpler to brick them, forcing the owners to upgrade to a modern and supported device.
Or upgrade them to modern OpenWrt, which has supported the near identical (minus USB port) D-Link DIR-882 since 2021: https://openwrt.org/toh/d-link/dir-882_a1 , as User 6SixTy has hinted at.
Re: Unauthenticated RCE in Motorola's MR2600 Router
#30Earlier quoted context omitted.
I would assume that liability is avoided when someone has done a reasonable effort to secure the device. The user needs to make sure they've secured their router from unauthorized access by using proper passwords. The ISP needs to make sure the router is delivered with the latest firmware and is pre-configured to be secure.
I would not assume that. Because British government has just made leaseholders of apartments liable for costs of fixing forged and fraudulently obtained fire safety certification of apartment blocks. The manufacturers of cladding materials have forged the fire safety certificate, the construction company has not followed the law when it comes to fire breaks and other fire safety system, the government building contro…
Known unsafe building methods should not have been legal, but we know that politicians have been avoiding legislating this specific issue for more 50 years[1]. Politicians need votes or kickbacks in months or a few years at most. Fire safety is a long term investment against a rare problem. Long term investments against even common problems are basically impossible in modern democracies. For example, if you legislate cycle path networks everywhere people will eventually love them and fight to keep them, in addition to delivering economic and health benefits, but outside the Netherlands very few places do it - because it took 40 years in the Netherlands.
[1]