Hard Coded Password Sinks Fleet of DSL Routers
ID: d6167a0c-0fde-5a65-810d-22dbfa660551
STIX ID: report--d6167a0c-0fde-5a65-810d-22dbfa660551
Feed Name: Security Ledger
**Hard-coded firmware password in DSL routers enables remote compromise** — CERT warns that a default administrator password pattern ("XXXXairocon", where XXXX are the last four digits of the device MAC) is present in firmware used by multiple DSL router models from vendors including ZTE, ASUS, DIGICOM, Observa Telecom, PLDT and Kasda. An attacker who can reach the device’s Telnet service can log in with administrative credentials; CERT reports no available firmware patch and recommends blocking Telnet and SNMP from untrusted sources as mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
