• Home
  • News
  • Artificial Intelligence
  • Internet of Things
  • Open Source
  • Hardware
  • Software
  • Security
  • Resources
  • Industry Voice
  • Data Strategy Spotlight
  • Newsletters
  • Resources
    • Inqlogo 120x194
      Five things you should look for in choosing a Testing provider

      Choosing a Testing Partner can be complex.  So what do you look for?  This guide offers insight into the qualities you must look for in choosing a Testing provider.  Download now to learn more.

      Download
      Inqlogo 120x194
      Your questions answered: How to protect your data in the cloud

      The number of successful cyberattacks per year per company has increased by 46% over the last four years. But what really needs to be considered when exploring a solution? What questions need to be asked? Download to find out...

      Download
      Find resources
      Search by title or subject area
      View all resources
  • Follow us
    • RSS
    • Twitter
    • LinkedIn
    • Newsletters
    • Facebook
    • Google+
    • YouTube
  • Newsletter
  • Industry Voice
  • Data Strategy Spotlight
The Inquirer
The Inquirer
  • Home
  • News
  • Artificial Intelligence
  • Internet of Things
  • Open Source
  • Hardware
  • Software
  • Security
The Inquirer
  • Security

ZTE router flaw put 400,000 Hyperoptic customers at hacking risk

Vulnerability lurked in the hardcode of the H298N router

ZTE's H298N router had a flaw that put thousands of Hyperoptic customers at hacking risk
ZTE's H298N router had a flaw that put thousands of Hyperoptic customers at hacking risk
  • Roland Moore-Colyer
  • Roland Moore-Colyer
  • @RolandM_C
  • 25 April 2018
  • Tweet  
  • Facebook  
  • Google plus  
  •  
  •  
  • Send to  
0 Comments

ROUTERS FROM FIBRE PROVIDER HYPEROPTIC contain a flaw that left up to 400,000 British users open to potential hacking.

The H298N routers Hyperoptic provides to its UK users come courtesy of Chinese electronics firm ZTE.

But security firm Context IS discovered that the devices contained "the combination of a hardcoded root account and a DNS rebinding vulnerability", which could have allowed an "internet-based attacker to compromise all customer routers of UK ISP Hyperoptic via a malicious webpage".

Nasty stuff, particularly as the there's no need for a hacker to be on the same network as a targeted router.

Once compromised, a hacker could carry out all manner of nefarious activity, such as sucking up the network's password, snooping on data, or slaving the router into a high-bandwidth botnet that could be used to conduct distributed denial of service attacks.

Working with its partner Which?, Context IS alerted Hyperoptic to the flaw. The broadband provider then jumped into action to plug the vulnerability, and so far there are no murmurs of the security hole being exploited.

"As soon as we were made aware of the concern, we immediately changed the passwords to safeguard these devices, and we have been working together with our supplier to implement new security controls so that our customers can be confident the concern has now been resolved," said Hyperoptic's chief customer officer Steve Holford.

It looks like the security hole can be firmly laid at the doorstep of ZTE. The Chinese company has come under scrutiny from the UK's National Cyber Security Centre (NCSC) which warned telecoms companies operating in Britain to avoid using ZTE tech.

According to Which? the NCSC's warning wasn't related to the router security woes faced by Hyperoptic, though we suspect the broadband provider will think twice about using ZTE routers in the future.

"All ISPs should take this seriously, and invest in thoroughly testing their consumer devices and their infrastructure if they are not already doing so," highlighted Daniel Cater, the security researcher at Context IS, the chap who discovered the router flaw. Sounds like a sensible approach to us, rather than immediately blame Chinese tech. µ

  • Tweet  
  • Facebook  
  • Google plus  
  •  
  •  
  • Send to  
  • Topics
  • Security
  • Hyperoptic
  • Security
  • router
  • zte
  • broadband
  • internet

INQ Latest

Opera Touch will give Android users an extra hand while they surf
Opera Touch will give Android users an extra hand while they surf

In case you want to lean nonchalantly against a wall

  • Software
  • 25 April 2018
iPhone X2: TSMC 'starts production' of Apple's A12 chip using 7nm process
iPhone X2: TSMC 'starts production' of Apple's A12 chip using 7nm process

Chipmaker promises a performance boost and significant power reduction

  • Phones
  • 25 April 2018
Amazon unveils in-car delivery service as the ultimate car boot sale
Amazon unveils in-car delivery service as the ultimate car boot sale

Smart tech means there's a deposit from a stranger coming to your rear end

  • Hardware
  • 25 April 2018
Facebook is making it tougher for third-party apps to scrape user data
Facebook is making it tougher for third-party apps to scrape user data

Firm shutters some APIs in wake of Cambridge Analytica scandal

  • Developer
  • 25 April 2018
Back to Top

Most read

OnePlus 6 release date, specs and price: OnePlus confirms 16 May launch event in London
OnePlus 6 release date, specs and price: OnePlus confirms 16 May launch event in London
Microsoft's Windows 10 April Update might be released today
Microsoft's Windows 10 April Update might be released today
iPhone X price, deals and news: Apple suppliers confirm iPhone X sales are plummeting
iPhone X price, deals and news: Apple suppliers confirm iPhone X sales are plummeting
Nvidia Tegra X1 flaw allows all Nintendo Switch consoles to be hacked
Nvidia Tegra X1 flaw allows all Nintendo Switch consoles to be hacked
Google looks set to offer Linux on Chromebooks in the next few months
Google looks set to offer Linux on Chromebooks in the next few months
  • Contact
  • Marketing solutions
  • Enterprise IT Events
  • About Incisive Media
  • Terms & conditions
  • Privacy policy
  • RSS
  • Twitter
  • LinkedIn
  • Newsletters
  • Facebook
  • Google+
  • YouTube

© Incisive Business Media (IP) Limited, Published by Incisive Business Media Limited, New London House, 172 Drury Lane, London WC2B 5QR, registered in England and Wales with company registration numbers 09177174 & 09178013

Digital publisher of the year
Digital publisher of the year 2010, 2013, 2016 & 2017