TP-Link Archer VR1600V V2 Super User Password Cracked
marcelvarallo.com
marcelvarallo.com
> it doesn’t exist and referred to the manual by the vendor.
This kind of flat out lying happens a lot. I suspect some of it is that the customer service teams have zero to no interaction with the developers, so if it's not written down it doesn't exist.
I think this is a good argument for developers spending at least some time working on customer service per week (even just a few hours). You could escalate queries such as this one to a developer, where clearly somebody is asking a more technical question.
Before anybody says "that's unrealistic, they don't have time" - first consider the amount of ridiculous meetings a developer will normally find themselves in, or how long they spend answering emails every day.
Of course, it doesn't mean that such a password would be given away, but at the very least it could start an internal discussion about it's existence. Having a single shared super-password is a problem waiting to happen.
Regarding the point with small firmware-based devices and security (i.e. IoT), I believe the practice is changing where each device will have entirely unique credentials (something that's relatively easy to do these days).
My company does this. (Or at least, did before the pandemic.)
My job is to build web sites. My company is in healthcare. that means this web dev has been literally hands-on with actual customers. Actual patients. And their children.
It really changes your view once you're back in the office in front of a keyboard. You start to think about what you design and build in a different way. You start to remember that the people using your web site aren't on the latest whiz-bank iPhone 16. They're on a craptastic pre-paid piece of garbage that they bought at 7-Eleven and share with other members of their family. A phone you and I would use as a weekend burner is all the internet access some people will ever have.
Your realization is spot-on, but what's disturbing is that this is done by having developers work front desk-ish and hoping they learn the lessons, instead of being imposed, top-down, from a higher level.
"We should write software for the kind of devices our users are using" isn't a story from the trenches, it's product and software development management 101. "We should target devices with these baseline specs" isn't something you get by having developers eyeball what phones their users are on, you get them by having Marketing put those fancy analytics tools that cost an arm and a leg every month to good use, and then by having those smart-ass program managers come up with a product definition that includes them, instead of the same generic "engaging, easy-to-use software that enables our customers to yadda yadda yadda" that gets cranked out each year.
This way everyone's writing against the same specs. Otherwise the two developers who ended up in the VIP clinic and have seen nothing but iPhones all day will keep cranking out the code that turns the phones everyone uses into egg frying machines, while the other guys will write lean, mean software that the UX lead and the CTO will laugh at and then they'll go berserk about how premature optimization is the root of all evil because they're on iPhones, too, and the whole thing work just fine.
My company is selling software for industry automation and the people using it often enough don't even have a PC at home. They learned using a PC at work and anything happening that isn't part of their trained workflow (sometimes even a simple additional optional input field) overwhelms them. Getting to know customers is very, very important for developers.
A long time ago, when I worked in video/TV production we had the regular gamut of high spec reference monitors (Barco, Sony, LG) and we also had a lot of $99 walmart specials. It was explained to me the editors and VFX had to make it look good on the cheap TV because that's where the video was going to be seen 99% of the time.
That perspective must be awesome in every aspect of the word: hope inducing and inspiring but also instilling a bit of fear in that real people, possibly sick or terminal people, will be using your work. I guess this is the mantle of “mission critical”.
All developers could benefit from direct interaction with the actual users
It's amazing the disconnect between the two groups. And it's not because someone is wrong, just that they have a different perspective of how to use something
whiz-bang
This is always a good idea; it fosters better teamwork throughout the organisation and makes the abstract work we do more concrete. The last time I did this I remember asking the person if the page load (on the internal system) was always so slow, they replied "yes" - next hackday I optimised it by a factor of 100. That's not something ops people will generally even know to ask for, but when they're dealing with a high call volume, that speed up is like an extra person.
I believe some regulations require unique credentials and this goes against that.
I guess in the future we'll see this even effect SMBs like the Raspberry Pi... I guess they will need some new methods for such devices to store a default password independent of the flashed OS?
It has no built-in storage and you cannot remotely access raspbian unless you modify the image to write 'ssh' in the root folder.
(I don't think pxe qualifies either)
I don't know about "per week" but definitely from time to time.
I've run some B2B companies selling to the enterprise and always had each member of the exec team come along on a sales call every quarter (obviously different calls!). This has been especially valuable for the CFO, the most inward-facing of executives. It's surprisingly common for the CFO not to really know what the product is beyond what's in the company's own sales literature and what comes through by what's discussed on the P/L. Very enlightening.
The support process should have a way of escalating to developers though. I've found plenty of bugs in products and had no way to get in contact with someone that would actually be interested in hearing it.
I pretty much agree with rblatz comment. From my opinion it's a good way to have high turnover of people I don't want on my team anyway.
Note I don't think developers are bad if they don't want to do customer support, but I am particularly interested in hiring product focused developers. That is, developers who really care not just about difficult technical problems, but who care about how solving those problems actually affect the customers for whom we're building the product.
I have found that, on the contrary, product-focused developers love doing customer support (some small portion of the time). They like to see how their features and fixes affect the customer experience, and they get a kick out of fixing small annoyances that overall build a more polished product, but might get just "triaged away" if it went through multiple levels of CS -> product manager -> engineers.
Another options is to have them sit with customer support and listening to their phone calls with them.
It might also be that while the developers might not be skilled enought in the problem domain to provide general support as many questions might be more general.
I think you are giving tp-link too much credit, that they want to build good devices.
Most products (including pretty much everything tp-link has) are mass market garbage, where the goal is to throw as many of them over the wall and hope some stick (and then milk the ones that stick).
By the time you buy device, developers are already working on next one. They only address issues that blow out.
Customer service in such cases is just minimum necessary that they can get away with. They are there more as damage control rather than actually helping users.
If they can have a choice of cheaper customers support (and development time), or better one, they will pick cheaper one 100% of time.
With such a competitive market (software developers), don't be surprised if my motivation is a bit lacking when I've got to respond to a bunch of people asking questions unrelated to the product.
> don't be surprised if my motivation is a bit lacking when
> I've got to respond to a bunch of people asking questions
> unrelated to the product.
I did suggest some kind of filtering where more technical questions could be passed on to developers. You would also expect the completely unrelated questions to be filtered.
But don't underestimate the power of the experience, if you've got 100 support tickets asking where the 'login' button is, maybe you'll be motivated to label it clearly with the word 'login' and not some icon that requires interpretation.
If you think about it, the power of agile development has really come from being more customer requirements focused, with quick rounds of feedback and review on deliverables and milestones. If you abstract the developers away from the feedback, how on earth can you expect them to make a decent end result?
Not so easy at all. I still see cheapest netdevs with same hardcoded, or random MAC addresses.
Cheapest devices are made with exactly zero per-device interactions/customisation. They are made to fly out from highly automated manufacturing lines like bullets from a machine gun.
Without any notice too - and I know a few businesses that were pretty upset with this. Particularly because many of their employees were working from home and 'in this climate'.
A commenter has also pointed out [2]:
> The Archer VR1600V software is licensed under the GPL. This can be used to compel TPG to release the source behind their modifications, if anyone wants to use the legal system to chase TPG for information.
Edit: I know that the version of OpenVPN on the router was using TLS 1.0, which is deprecated in all clients now. That's besides the matter. I don't believe it's an ISPs role to be fiddling with the application level services of someone's internet.
[1]: https://community.tpg.com.au/t5/Broadband-Internet/Missing-V...
[2]: https://www.marcelvarallo.com/some-more-fiddling-with-the-ar...
It is not but it doesn't mean they won't do it. I am lucky enough to be unlucky enough to be using VDSL2, so I use my own CPE where possible, and often just disable the TR069 interface and CWMP functionality so the ISP can't break into my modem.
The reason for this is they often factory reset the modem if their automated auditing scripts notice something "forbidden", i.e. DMZ to my router, which causes me great inconvenience to have to log into the modem again and setup a DMZ. Same would happen if I was using (soft-disabled) Bridge mode.
So I just deny them access. On some modems I also download the config, change SSH and Telnet password (as well as "admin" and "telecomadmin" passwords for web UI), remove CWMP entries completely, and then restore the config so the modem won't connect.
Best part is, if I have a problem that I have to report to the ISP, I first factory reset the modem, it pulls the config via TFTP on TR069 interface, resets again and configures itself according to their wishes - then I try to reproduce the problem, and if it is present, I call them to open a support ticket. If it is not present, I roll back to my config and try to debug the issue on my side.
No harm to the modem, no time wasted for me.
Sadly this is not at all possible for DOCSIS cable modems nor GPON ONTs for fiber to the home service. There you're SOL if your ISP is being mean and displaying anti-user behavior.
All interfaces are separate, and if you bridge your modem it only bridges HSI on LAN1. Phone works, IPTV on LAN 2 and 3 works and of course TR069 works.
If on xDSL, ISP can see all stats on their end of the DSLAM, there is literally nothing to configure from the modem side, except maybe turn on/off certain modes, but by default they're all turned on.
This makes basic connectivity between the Zyxel box acting as a modem and the TR069 server challenging, though perhaps not impossible (you could, say, allocate a small IPv6 prefix to the modem, but I'm not sure if A&A's TR069 servers work over an IPv6 only connection).
You can "easily" replace the Freebox, provided you can:
A) find the necessary ipip6 configuration for your region
B) you don't mind losing VOIP and IPTV
It should even be possible to retain IPTV if you route the correct VLAN to their set-top box, but I didn't care enough to go through that.
The amazing part to me is that (IMO) they are selling you a more expensive monthly subscription to get an all-in-one box with a less terrible WiFi implementation. [1]
The standard WiFi experience with their lower-tier all-in-one is terribad, which could easily be solved by buying a WiFi AP and plugging it into their box via Ethernet.
German ISPs do the same thing, by offering you the choice of a basic router or a Fritz!Box for a higher fee. In every instance I have seen, you're better off selecting the cheapest device your ISP will provide, putting it into bridge mode, and using your own router/AP via Ethernet.
That's true, but pretty much everyone chooses the Fritz!Box, cause they're just that great for the price. Easy to use, lots of functionality, and actually really great performance. For a home router, at least.
Plenty of places, and it can be fairly cheap. Here's Ubiquiti's selection for example [0], the basic one is $45-50 [1] (and less in quantity). I don't recommend Ubiquiti stuff much anymore because the company has gone to shit overall sadly, but for specific dedicated application stuff they're still a worthwhile data point. GPON into an SFP is interesting too.
>And how do you clone the serial number of the ONU?
Actually getting support from the ISP for your own CPE would often be the stickier wicket I suspect. My fiber comes from a nice local ISP I've worked with for 20+ years now, I can get right to senior techs and they're happy to do whatever, and indeed are happy to use me as a guinea pig for trying out equipment. Getting the right OLT profile and auth info was just a matter of contacting them. Of course for that very reason it's less important since they're not messing with anyone's stuff anyway. Maybe the kind of ISP you'd most want your own full stack for in most instances is also the kind that'd make it harder/refuse? Though sometimes I've been surprised and with dedication/effort one can slip through the cracks or find an SMB angle.
----
0: https://store.ui.com/search?mockup=gpon&q=gpon*
1: https://www.balticnetworks.com/ubiquiti-ufiber-loco-high-per...
Also, most widely sold Unifi equipment is expensive, cheaper devices are very rare to find in limited markets.
I would not consider this available if I have to order it from another country and pay customs + wait weeks for delivery.
And again, the equipment has to be whitelisted by the OLT and most ISPs don't want to that. And cloning the S/N is difficult/impossible.
I think we have two different kinds of ISPs in mind. I'm talking about mass-market monopolies, and you're talking about "artisanal" small ISPs where you can walk into the CEOs office and pass a rack of routers on the way there.
My isp is the former telecommunications monopoly in my country, not a artisinal isp and they still allow using your own cpe.
And it's great your ISP doesn't use Huawei OLTs which only work with Huawei ONUs, so you can plug the fiber directly into the ERx and setup a connection either as IPoE, PPPoE or just DHCP client on a VLAN.
It is my understanding that subscribers with a Freebox Delta only receive this, since the Delta is SFP+ capable. Since I have the older Freebox Revolution the ISP provided me a media converter which accepts the ONU and provides a normal SFP port which can be plugged into a normal device with an SFP port. [2] Then, you just have to configure the ipip tunnel on your device and you're online.
[1] https://lafibre.info/images/pon/201012_SFP_Free_FTTH_10G-EPO...
[2] https://lafibre.info/gpon/olt-sfp-possible-revolution/msg433...
(and other countries on the Balkans, it's all Huawei all-in-one GPON CPE everywhere!)
Telekom Srbija (Serbia)
SBB (Serbia)
Orion telekom (Serbia)
Supernova (Serbia)
A1 Slovenia
Telekom Slovenije (Slovenia)
Telemach (Slovenia)
A1 HR (Croatia)
Telemach (Croatia)
T-Com (Croatia)
Iskon (Croatia)
Telekom Srpske (Bosnia and Herzegovina)
Telemach (Bosnia and Herzegovina)
Triontel (Bosnia and Herzegovina)
Mtel (Montenegro)
T-Com (Montenegro)
T-Com (North Macedonia)
A1 (North Macedonia)
... and similar in Bulgaria
On all relevant websites, you cannot find info on BYO, and I can personally guarantee you cannot use your device on GPON or DOCSIS networks.
Only Romania is an exception.
So DOCSIS is hell.
GPON is ... depends. The technology is great, but some ISPs can and will ruin it because they're greedy and shortsighted. Someplaces you can get a bridge CPE (ONT) that does have remote access but doesn't allow configuration, someplaces the ONT itself is fine (i.e. HG8245 series for which too you can disable TR069 interface and CWMP and change the passwords - which I did), but someplaces you just get the "DOCSIS over fiber" experience, with hostile ONT in your home network the ISP uses to make your existence miserable.
Personally, DSL is fine for me. I am so used to low speeds (~20/2 Mbps) when I am in the village (since march due to COVID, working from home), I have started bonding [0] DSL and LTE for around 95/45 Mbps and that is fine for me.
So, I'd rather stay on tried-and-true, stable, low ping DSL, than muck around with DOCSIS and fear any rain or wind.
For GPON it depends on the ISP, but the technology does not dictate any remote management requirements except OMCI which is not concerned with "higher layer" configuration such as WiFi or router features.
[0] https://milankragujevic.com/openmptcprouter-true-bonding-of-...
The prevailing issue is the way the US regulates ISPs leading to a lack of competition, giving them little incentive to do anything other than raise prices on a regular basis. While I have at least talked to technical support people who understand the concept of a cable modem being supported or not, there is no one available you can talk to who understands signal levels, etc. The only diagnostic they can perform is "does speedtest show the advertised speeds".
There is still some sort of issue with the cable modem getting "stuck" in a bad state. I have a USB controlled relay that is used each morning to interrupt the DC power to the cable modem. This basically fixes it. I'm not awake when the modem resets so it is a non issue to me.
Being able to use your own modem would fix a lot of problems I have with DOCSIS ISPs, but sadly there's no regulation for it. So yeah, you have to use theirs.
edit: funnily enough, DSL is similar to AON in that it's dedicated last mile
I doubt many of the modifications done for them fall outside of flicking random config switches on/off and making sure the factory config will provision properly.
Most of the source drops I see from embedded hardware manufacturers aren't usable out of the box for one reason or the other anyway. Open source devs won't touch a lot of Broadcom hardware just because the driver situation is an unabated nightmare.
Despite this, many/most of the TPG (2nd/3rd largest Australian ISP) customers will have to keep their VR1600V's connected in some form anyway, as they provision the sip credentials to them, and refuse to allow you to use your own voip hardware...
In various periods of distrust for my ISP, I have also run the external interface of my NAT through a public VPN provider, and added monitoring to look for connection slowdowns or open ports on the router, as evidence of a compromise. So far it's just been jumping at shadows, though.
Regular modems are the least annoying bet however. They simply hand over an IP address and then act as a transparent coax <--> Ethernet bridge
minor edit: changed "vendor" to "ISP" to avoid confusion
I contacted them and told them to upgrade the router and close the ports. Didn't get a reply but the ports were closed after a while so I thought that was that.
Fast forward to a few weeks back - I was playing around with RoMON settings on my MikroTik router (it's their proprietary protocol for debugging/proxying/chaining routers behind nat so if you mess up the config you can still access it). Lo and behold - over 150 MikroTik routers, all one hop way from each other, all with RoMON on for all ports. All over the city judging form the AP names. All outdated as well.
And to make matters worse - they hadn't even upgraded the one router upstream from me that I complained about in the first place!
Needless to say, I don't trust it and disable it whenever I can. I can set up my PPPoE or VoIP access myself.
But as I alluded in my original post, since it seems like my ISP doesn't do any monkey business, I mostly leave it off. I have specific services running in my network that use it, but my vanilla traffic is unencrypted from my router.
That said, even with no VPN I have a pihole backed by DNS-over-HTTPS, and almost all traffic (above 95%) goes over HTTPS or SSH anyway.
The hard coded su password only exists in the TPG (an Australian ISP) version of the VR1600v software. The main admin user is unable to set VOIP server details and authentication etc.
If you get a vanilla TP-Link VR1600v, you'll find there is no such hardcoded password, and the normal admin account has full access to VOIP and CWMP settings.
A little older since the web archive snapshot of today are erroring out too.
[1] = https://whrl.pl/Rgapje
>This snapshot cannot be displayed due to an internal error.
archive.org, never change.
> chaotic atmosphere of 2020, the Wayback Machine is a
> crucial resource in the fight against disinformation, and
> now more than ever we need your help.
It was working earlier... What was that about not letting them change history?
I also hear that the Wayback machine has also been involved in censorship of some content, something I don't think they should do unless the case is extreme (which there are few).
The only form of disinformation the Wayback machine should be responsible for fighting is that of historical changes, not the content itself.
> archive.org, never change.
I recently started a scheduled donation to archive.org due to my fear that it can get worse...
VExy!64a3ngI guess we have to do something with it eventually. Probably widespread ban of import of devices with security issues in its design will do.
How is this not fraud? If anyone can just lie with no consequence, how will the consumer ever find a company that does take security seriously?
VExy!64a3ngThere's no TP-Link VT1600V product. They do make a VR1600V, though.