4 ms·
CVE-2024-6045 - https://nvd.nist.gov/vuln/detail/CVE-2024-6045 https://nvd.nist.gov/vuln/detail/CVE-2024-6045 > Certain models of D-Link wireless routers conta
by skilled 2y ago
CVE-2024-6045 - https://nvd.nist.gov/vuln/detail/CVE-2024-6045 https://nvd.nist.gov/vuln/detail/CVE-2024-6045
> Certain models of D-Link wireless routers contain an undisclosed factory testing backdoor. Unauthenticated attackers on the local area network can force the device to enable Telnet service by accessing a specific URL and can log in by using the administrator credentials obtained from analyzing the firmware.
- WhatsName 2y agoHow would anyone tell if this is not malicious in the first place? It quacks like a backdoor, looks like a backdoor...
- sph 2y agoOn security issues from massive Internet appliance vendors, you can safely assume it is malicious, though it might not have been placed there with knowledge of the vendor itself (i.e. it's very likely a state actor)
- consp 2y agoI much rather assume it's cost cutting in combination with poor testing practices. Which is also more likely.
- arp242 2y agoIf a state actor has access to your LAN you're all kinds of fucked already. They really don't need this crummy exploit for crummy home routers. It's pretty far-fetched to suspect a state actor, and outright ridiculously conspiratorial to say we can "safely assume" this.
- MaxikCZ 2y agoNoone said its "your state" actor.
- ndsipa_pomu 2y ago> If a state actor has access to your LAN you're all kinds of fucked already. Seems very likely that some IOT devices are connected to LANs and can be used for shenanigans which is why you shouldn't trust anything on your LAN and always require encryption/authentication. Having telnet available on a router is beyond stupid and outright malicious.
- mijoharas 2y agoHanlon's razor would disagree with you.
- colordrops 2y agoHanlons razor is used by the malicious to fool the stupid
- account42 2y agoThat's an opinion, not an argument.
- mijoharas 2y agoAgreed, as is the point I was responding to.
- remram 2y agoSomeone putting in a backdoor would have known it's a backdoor, and I feel like they would have done it better. For example, making sure the hardcoded password can't be recovered from the firmware.
- deleted 2y ago[deleted]