» ISP News » 

BT Wi-Fi Extenders Can Expose Your Wireless Network Password

Wednesday, September 21st, 2016 (9:18 am) by Mark Jackson (Score 1,052)
bt_wifi_extender_300

The network security gurus at Pen Test Partners have warned owners of BT’s Wi-Fi Extender 300 (Broadband Extender 300 Kit) adapters to update its firmware after they uncovered a string of vulnerabilities that could result in your home WiFi network password being leaked.

The 300 series WiFi extenders are single band (2.4GHz) 802.11n spec devices that offer a headline maximum wireless network speed of 300Mbps (150Mbps in 20MHz mode and 300Mbps in 40MHz mode) and as such they’ve largely been superseded by the dual-band 600 and faster series. Never the less you can still buy them for only £19.99 a pop.

However anybody who has brought one of the 300 series adapters should be aware that hackers can exploit a number of vulnerabilities in the device in order to steal your WPA passphrase (wireless network password).

According to PTP, the adapters are open to a Cross-Site Request Forgery (CSRF) attack in their web interface and other Cross-Site Scripting (XSS) vulnerabilities that can be combined. “Authentication bypass is not good. Together with the XSS and some poor UI design, this means I can steal your Wi-Fi password. (XSS allows us to bypass Same Origin Policy),” said PTP.

PTP Advice for the vendor:

PDP wrote a very good series of articles, a great many years ago, on the early Home Hubs – [BT] made a lot of the same mistakes again. The people writing and QAing this software need to have a better understanding of security issues. Some checking of third party products would seem to be in order, before they are released to the general public.

PTP first became aware of the problems when they purchased an adapted in mid-July 2016 and to BT’s credit the operator was able to patch all of the issues and release a new firmware (v1.1.8) before the end of August 2016, which can be Downloaded Here.

PTP also says it’s best to log in, change the password and not use the “remember me” function in either Wi-Fi device or the “remember password” function in the browser.

A Spokesperson for BT said (The Register):

“We are grateful to Pen Test Partners for alerting us to this issue. We have been working to address this potential weakness and issued an update which corrected the problem in August 2016. We are not aware of any cases where customers have suffered any issues. Customers should ensure they download the firmware update from the BT website.”

BT has chosen to list the firmware changes for v1.1.8 as “Bug fixes“, although perhaps “Security fixes” would have been better in order to encourage end-users to update. The actual process of updating should be fairly simple and involves using the largely automated BT Device Configuration Tool (software).

Delicious
Add to Diigo
Leave a Comment
0 Responses

Comments are closed.

IMPORTANT: Javascript must be enabled to post (most browsers do this automatically). On mobile devices you may need to load the page in 'Desktop' mode to comment.


Comments RSS Feed

* Your comment might NOT appear immediately (the site cache re-syncs periodically) *
* Comments that break our rules, spam, troll or post via fake IP/proxy servers may be blocked *
Promotion
Cheapest Superfast ISPs
  • Origin Broadband £23.89 (*31.58)
    Up to 38Mbps, Unlimited
    Gift: None
  • Plusnet £24.99 (*33.98)
    Up to 38Mbps, Unlimited
    Gift: £50 Reward Card
  • TalkTalk £25.00 (*33.50)
    Up to 38Mbps, Unlimited
    Gift: None
  • Vodafone £25.00
    Up to 38Mbps, Unlimited
    Gift: Gift Worth up to £199
  • Hyperoptic £26.00 (*35.00)
    Up to 100Mbps, Unlimited
    Gift: None
Prices inc. Line Rental | View All
Poll
*Javascript must be ON to vote*
The Top 20 Category Tags
  1. BT (1937)
  2. Broadband Delivery UK (1326)
  3. FTTP (1256)
  4. FTTC (1230)
  5. Politics (959)
  6. Openreach (957)
  7. Business (860)
  8. Statistics (774)
  9. Fibre Optic (753)
  10. Mobile Broadband (704)
  11. Wireless Internet (637)
  12. Ofcom Regulation (633)
  13. Virgin Media (587)
  14. 4G (587)
  15. FTTH (523)
  16. Sky Broadband (460)
  17. TalkTalk (439)
  18. EE (378)
  19. Security (314)
  20. 3G (274)
New Forum Topics
Helpful ISP Guides and Tips
»
»
»
»
»
»
»
»
»
»
»
»
»
»
»
»
»
»
»
»
»
»
»
»
»
»
»
Promotion

Copyright © 1999 to Present - ISPreview.co.uk - All Rights Reserved - Terms  ,  Privacy and Cookie Policy  ,  Links  ,  Website Rules