TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Modems distributed by AT&T vulnerable

20 pointsby crgtover 7 years ago

4 comments

lakenover 7 years ago
I don&#x27;t understand how so many internet connected device&#x27;s manufacturers don&#x27;t even <i>think</i> to check if they have an open ports, <i>especially</i> an open SSH port. Or is it that they just don&#x27;t care? I can&#x27;t tell anymore.
评论 #15152329 未加载
评论 #15151798 未加载
yegleover 7 years ago
I&#x27;m very interested to get a copy of the said vulnerable firmware to poke around. How can I get one?<p>One use case is for ATT Fiber users to get the 802.1x certificate from the router, and use your own router instead (RouterOS etc.).
评论 #15151911 未加载
评论 #15152066 未加载
anonovaover 7 years ago
Another popular and flawed modem Arris released into the wild is the SB6190. You can easily DoS it: <a href="https:&#x2F;&#x2F;www.dslreports.com&#x2F;shownews&#x2F;Puma-6-Flaw-Lets-Attackers-Bog-Down-Impacted-Modems-Gateways-139486" rel="nofollow">https:&#x2F;&#x2F;www.dslreports.com&#x2F;shownews&#x2F;Puma-6-Flaw-Lets-Attacke...</a>
sjbaseover 7 years ago
&gt; &quot;There’s no way people are not exploiting this in the wild&quot;<p>Hard to disagree there.<p>Does it really usually take 2 months for something like this to get disclosed? Seems like anyone bored enough to run a SYN scan on one of these would find the vulnerable services instantly.