Home
 » ISP News » 
Sponsored Links

BT Wi-Fi Extenders Can Expose Your Wireless Network Password

Wednesday, Sep 21st, 2016 (9:18 am) - Score 2,955

The network security gurus at Pen Test Partners have warned owners of BT’s Wi-Fi Extender 300 (Broadband Extender 300 Kit) adapters to update its firmware after they uncovered a string of vulnerabilities that could result in your home WiFi network password being leaked.

The 300 series WiFi extenders are single band (2.4GHz) 802.11n spec devices that offer a headline maximum wireless network speed of 300Mbps (150Mbps in 20MHz mode and 300Mbps in 40MHz mode) and as such they’ve largely been superseded by the dual-band 600 and faster series. Never the less you can still buy them for only £19.99 a pop.

However anybody who has brought one of the 300 series adapters should be aware that hackers can exploit a number of vulnerabilities in the device in order to steal your WPA passphrase (wireless network password).

According to PTP, the adapters are open to a Cross-Site Request Forgery (CSRF) attack in their web interface and other Cross-Site Scripting (XSS) vulnerabilities that can be combined. “Authentication bypass is not good. Together with the XSS and some poor UI design, this means I can steal your Wi-Fi password. (XSS allows us to bypass Same Origin Policy),” said PTP.

PTP Advice for the vendor:

PDP wrote a very good series of articles, a great many years ago, on the early Home Hubs – [BT] made a lot of the same mistakes again. The people writing and QAing this software need to have a better understanding of security issues. Some checking of third party products would seem to be in order, before they are released to the general public.

PTP first became aware of the problems when they purchased an adapted in mid-July 2016 and to BT’s credit the operator was able to patch all of the issues and release a new firmware (v1.1.8) before the end of August 2016, which can be Downloaded Here.

PTP also says it’s best to log in, change the password and not use the “remember me” function in either Wi-Fi device or the “remember password” function in the browser.

A Spokesperson for BT said (The Register):

“We are grateful to Pen Test Partners for alerting us to this issue. We have been working to address this potential weakness and issued an update which corrected the problem in August 2016. We are not aware of any cases where customers have suffered any issues. Customers should ensure they download the firmware update from the BT website.”

BT has chosen to list the firmware changes for v1.1.8 as “Bug fixes“, although perhaps “Security fixes” would have been better in order to encourage end-users to update. The actual process of updating should be fairly simple and involves using the largely automated BT Device Configuration Tool (software).

Mark-Jackson
By Mark Jackson
Mark is a professional technology writer, IT consultant and computer engineer from Dorset (England), he also founded ISPreview in 1999 and enjoys analysing the latest telecoms and broadband developments. Find me on X (Twitter), Mastodon, Facebook and .
Search ISP News
Search ISP Listings
Search ISP Reviews

Comments are closed

Cheap BIG ISPs for 100Mbps+
Community Fibre UK ISP Logo
150Mbps
Gift: None
Virgin Media UK ISP Logo
Virgin Media £26.00
132Mbps
Gift: None
Shell Energy UK ISP Logo
Shell Energy £26.99
109Mbps
Gift: None
Sky Broadband UK ISP Logo
100Mbps
Gift: None
Plusnet UK ISP Logo
Plusnet £27.99
145Mbps
Gift: None
Large Availability | View All
Cheapest ISPs for 100Mbps+
Gigaclear UK ISP Logo
Gigaclear £17.00
200Mbps
Gift: None
YouFibre UK ISP Logo
YouFibre £19.99
150Mbps
Gift: None
Community Fibre UK ISP Logo
150Mbps
Gift: None
BeFibre UK ISP Logo
BeFibre £21.00
150Mbps
Gift: £25 Love2Shop Card
Hey! Broadband UK ISP Logo
150Mbps
Gift: None
Large Availability | View All
The Top 15 Category Tags
  1. FTTP (5524)
  2. BT (3518)
  3. Politics (2540)
  4. Openreach (2298)
  5. Business (2264)
  6. Building Digital UK (2246)
  7. FTTC (2044)
  8. Mobile Broadband (1975)
  9. Statistics (1788)
  10. 4G (1666)
  11. Virgin Media (1621)
  12. Ofcom Regulation (1463)
  13. Fibre Optic (1395)
  14. Wireless Internet (1389)
  15. FTTH (1381)

Helpful ISP Guides and Tips

Promotion
Sponsored

Copyright © 1999 to Present - ISPreview.co.uk - All Rights Reserved - Terms , Privacy and Cookie Policy , Links , Website Rules , Contact
Mastodon