Unauthenticated RCE in Motorola's MR2600 Router
mrbruh.com
mrbruh.com
I wonder how this would hold up in court, couldn't you argue that routers are generally buggy, how can they force any responsibility if they can easily be hacked?
Because British government has just made leaseholders of apartments liable for costs of fixing forged and fraudulently obtained fire safety certification of apartment blocks.
The manufacturers of cladding materials have forged the fire safety certificate, the construction company has not followed the law when it comes to fire breaks and other fire safety system, the government building control has examined the building and signed it off as correct, possibly corruptly.
But after a skyscraper burned down with all the residents inside, now the residents are liable.
Known unsafe building methods should not have been legal, but we know that politicians have been avoiding legislating this specific issue for more 50 years[1]. Politicians need votes or kickbacks in months or a few years at most. Fire safety is a long term investment against a rare problem. Long term investments against even common problems are basically impossible in modern democracies. For example, if you legislate cycle path networks everywhere people will eventually love them and fight to keep them, in addition to delivering economic and health benefits, but outside the Netherlands very few places do it - because it took 40 years in the Netherlands.
[1]
Nah, it’s corruption the CEO of the company that forged fire safety documents was given legal immunity.
https://www.mwl-law.com/wp-content/uploads/2018/02/OWNER-LIA...
Germany has some sensible laws about personal responsibility, like it being an offence to run out of gas on the autobahn and seriously treating driving in general as a privilege. But it requires a certain cultural mindset.
The “old” Motorola router division Motorola Home got sold to Arris _without_ the brand name in 2013, and then the brand name went to Zoom in 2016. Zoom merged with another vendor called Minim, went bankrupt in 2023, and the assets were bought by a company called e2Companies in 2024.
So e2Companies is who the author should email, but good luck. I’m shocked these were even “maintained” until 2024.
>vender doesn’t want to fix it
Sometimes I wonder if the white hat hackers who find such a thing should just take it a step further and patch those hosts. Take the firmware, fix those bugs and update those 42 routers.
But it’s definitely not white hat.
There's already an OpenWRT image for the DLink model, so coming up with an entry for the Motorola version shouldn't be hard.
https://www.zdnet.com/article/a-mysterious-grey-hat-is-patch...
A search of "router/firmware/query.aspx" leads me to D-Link endpoints who also uses the "wrpd" subdomain.