• About
  • Advertise
  • Careers
  • Contact
Sunday, November 9, 2025
No Result
View All Result
NEWSLETTER
iotlasvegas
  • Home
  • Internet of Things
  • Security
  • Mobile
  • Networking
  • Smart Cities
  • Development
  • Data & Analytics
  • Enterprise
  • Home
  • Internet of Things
  • Security
  • Mobile
  • Networking
  • Smart Cities
  • Development
  • Data & Analytics
  • Enterprise
No Result
View All Result
iotlasvegas
No Result
View All Result
Home Security

Residential routers easy to hack

in Security
Residential routers easy to hack
0
SHARES
16
VIEWS
Share on FacebookShare on Twitter

The infamous “admin” user ID and hackable, weak passwords are prevalent on large numbers of home routers, says a security firm. That’s despite the public’s increasing awareness of vulnerabilities and associated hacking.

Researchers at ESET recently tested more than 12,000 home routers and found that many of the devices are insecure. Firmware was flawed in some cases.

+ Also on Network World:Answers to ‘Is the internet broken?’ and other Dyn DDoS questions +

“Approximately 7 percent of the routers tested show vulnerabilities of high or medium severity,” ESET says in an article on its Welivesecurity editorial website. “Fifteen percent of the tested routers used weak passwords, with ‘admin’ left as the username in most cases.”

Weak passwords can be easily exploited. Fourteen percent of simulated attacks on the routers were, in fact, victorious. The probing attack methodology was simply to use common default usernames and passwords, along with some frequently used combinations.

Telnet was left open on 20 percent of the routers, and command injection vulnerabilities were also caught.

Telnet, as an unsecured service, shouldn’t be openly available to even a local network, ESET explains. Command injection vulnerabilities “aim for the execution of arbitrary commands on the host operating system.” They use a vulnerable application, the security company says. Proper input validation fixes the deficiency.

Of that 7 percent of the now-common household devices with software vulnerabilities, about half (53 percent) had “bad access rights vulnerabilities,” or permissions problems, in other words.

The command injection vulnerabilities made up 39 percent of the failings. Cross-site scripting (XSS) vulnerabilities, which allow hackers to change router setups and run bogus scripts, made up 8 percent.

“The results clearly show that routers can be attacked fairly easily,” the article says.

ESET also says port scanning during its testing showed that in numerous cases, network services were accessible from internal networks, as well as from external networks.

Are your IoT devices vulnerable?

With the partial collapse of the internet last week, reportedly caused by home network Internet of Things (IoT) security cameras creating holes for DDoS attacks, I’m reminded of the Shodan IoT open port searching website that I wrote about in 2014.

Shodan, still active, is a search engine that trawls the internet looking for port-connected devices. Mapped, visual representations of connected IoT devices, such as open cameras around the world, are depicted.

Interestingly, Reddit-user Fistagon7 points out that Shodan services can be used to see if Reddit members participated in the aforementioned, and now-famous, IoT-originating DDoS attack last week.

“Scan your IoT devices to see if they may have participated in yesterday’s DDoS,” Fistagon7 writes, linking to a new version of Shodan.

That refreshed page, called the Internet of Things Scanner, powered by BullGuard, allows users to check if devices on a network are publicly accessible from the internet.

Open ports that might be indicative of a vulnerability are supposed to show up in the scans.

If open ports are found, Internet of Things Scanner will advise on corrective action, which can include modifying the router’s configuration. That might include restricting access to the port if you didn’t purposefully open the port.

“If you deliberately opened this port to enable specific device functionality, then you’re probably OK,” the results page says.

Join the Network World communities on Facebook and LinkedIn to comment on topics that are top of mind.
Download Best WordPress Themes Free Download
Download WordPress Themes Free
Premium WordPress Themes Download
Download Best WordPress Themes Free Download
free download udemy course
download samsung firmware
Premium WordPress Themes Download
free download udemy paid course
Tags: Residential routers easy to hack
Next Post
ARM builds up security in the tiniest IoT chips

ARM builds up security in the tiniest IoT chips

Recommended

The merged NXP and Freescale will make cars smarter from bumper to bumper

IoT standards groups get ready to rumble at CES

Facebook Twitter Youtube RSS

Newsletter

Subscribe our Newsletter for our latest updates.

Loading

Category

  • AI
  • Careers
  • Cloud Computing
  • Connected Cars
  • Connected Vehicles
  • Data & Analytics
  • Data Center
  • Data Centers
  • Databases
  • Development
  • Enterprise
  • Hardware
  • Healthcare
  • IIoT
  • Infrastructure
  • Internet of Things
  • IoT
  • IT Leadership
  • Manufacturing
  • Mobile
  • Networking
  • Oil & Gas
  • Open Source
  • Security
  • Smart Cities
  • Smart Homes
  • Software
  • Software Development
  • Standards
  • Technology Industry
  • Uncategorized
  • Unified Communications
  • Virtualization
  • WAN
  • Wearables

About Us

Advance IOT information site of Las Vegas USA

© 2024 https://iotlasvegas.com.

No Result
View All Result
  • Home
  • Internet of Things
  • Security
  • IoT
  • Mobile
  • Networking
  • Smart Cities
  • Development
  • Data & Analytics
  • Enterprise

© 2024 https://iotlasvegas.com.

Login to your account below

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In