Multiple Vulnerabilities in BHU WiFi “uRouter”

Nod

Honorary Master
Joined
Jul 22, 2005
Messages
10,968
Reaction score
2,716
Location
Darling
Source: IOActive
A Wonderful (and !Secure) Router from China

The BHU WiFi uRouter, manufactured and sold in China, looks great – and it contains multiple critical vulnerabilities. An unauthenticated attacker could bypass authentication, access sensitive information stored in its system logs, and in the worst case, execute OS commands on the router with root privileges. In addition, the uRouter ships with hidden users, SSH enabled by default and a hardcoded root password…and injects a third-party JavaScript file into all users’ HTTP traffic.

In this blog post, we cover the main security issues found on the router, and describe how to exploit the UART debug pins to extract the firmware and find security vulnerabilities.

Souvenir from China

During my last trip to China, I decided to buy some souvenirs. By “souvenirs”, I mean Chinese brand electronic devices that I couldn’t find at home.
I found the BHU WiFi uRouter, a very nice looking router, for €60. Using a translator on the vendor’s webpage, its Chinese name translated to “Tiger Will Power”, which seemed a little bit off. Instead, I renamed it “uRouter” based on the name of the URL of the product page – http://www.bhuwifi.com/product/urouter_gs.html.
img1.png

Rest of the article and analysis as the link above.

Be careful what you buy in China, and where you use it.
 
Wonder how secure Xiaomi routers are, they seem good and very cheap.
 

The only reason could be because someone would like to have an open door to your home.
It might be there because of "support" purposes, but this is seldom used these days, so does not fly.
 
Top
Sign up to the MyBroadband newsletter
X