Tengda vro discovers Backdoor

Source: Internet
Author: User

After a backdoor was found on the D-Link router, the security researcher found a backdoor in Tenda, another router manufacturer. The security researchers analyzed the latest firmware of W302R on the Tenda router and found an independent thread named MfgThread. It bundled port 7329 to receive UDP packets and will respond to commands containing special characters, these special characters include e, 1, and X. For e, a predefined string is returned, which is basically a ping test. For 1, it allows you to run the iwpriv command. The iwpriv command can be used to configure the vro network port. For X, it gives you root permission and can execute any command.

The author believes that this backdoor may first be implemented on the W302R router of tengda, and exists in the router MWN-WAPR150N of the W330R router and Medialink router.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.