Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So far I think tp-link locked down just the web interface. I believe it is still possible to flash via tftp and some other methods.

When tp-link plug these holes there will still exist many exploits possible to get root access and if not we will have to flash it through SPI.

Edit: here is one of the first exploits available: https://forum.openwrt.org/viewtopic.php?id=63123



This can be easily "fixed" by making the SoC check RSA signatures on flash contents.

It all really depends on how much the FCC will be willing to bother hardware vendors whose products end up as popular hack platforms.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: