3 ms·
I already have little hope for consumer networking equipment, this just seems like a big old list of scraped CVE's. One has to remember that the majority of th
by Namidairo 5y ago
I already have little hope for consumer networking equipment, this just seems like a big old list of scraped CVE's.
One has to remember that the majority of the development ends up being by the SoC vendor, usually a horribly out of date fork of OpenWrt with weird looking proprietary kernel modules to support wifi, accelerated nat, etc.
Quite a few of the older devices lack some pretty basic mitigations as well; ASLR, Position Independent Executables, Stack Canaries, etc. Either they get forgotten or they're off because of they can't be bothered getting the drivers up to scratch. (Assuming they haven't just been handed a binary)
- tim333 5y agoI'm surprised my very cheap and crappy consumer router doesn't seem listed anywhere (Technicolor TG588 v2)