Responsible disclosure for the win. It's a good thing nobody else is looking for vulnerabilities in these routers.
Responsible disclosure for the win. It's a good thing nobody else is looking for vulnerabilities in these routers.
As the article says the manufacturer has acknowledged the vulnerability, but I have not heard from them for quite a while. I've begun to wonder how much time has to pass without a fix before it would be irresponsible of me not to fully disclose the vulnerability. Lately I've been thinking that full disclosure may be the only responsible way to disclose a vulnerability. But I am still conflicted.
If you release it, you force the manager to do the right thing, and the developer will then be officially allowed time to fix it.
Give them a deadline and drop it. Even ZDI does this now. Some companies will sit on reports for years, because no one cares.