ZTE Router Vulnerabilities: A Demonstration on the Security Risks of the IoT

No ratings

Presented at InfoSecurityEurope 2019 by

Positive Technologies researchers have discovered a number of vulnerabilities in a ZTE wifi router, used by 750-800 thousand devices globally. This presentation will show that this router, from a well-respected vendor, was even in 2018 susceptible to use of dictionary of default credentials on privileged accounts, remote code execution via http on the system, and susceptibility to buffer overflow - to name just a few. This presentation will look in depth at the vulnerabilities we discovered including a demo, the risks associated with each flaw, how they can be addressed, and lessons we can learn for IoT security.Learning Outcomes:Audiences will understand the specific vulnerabilities discovered in the ZTE wifi routerAudiences will understand the dangers associated with each vulnerabilityAudiences will get practical advice on how to combat each vulnerabilityAudiences will gain greater insight into security and the IoT, with ZTE vulnerabilities as a case study exampleAudiences will understand what needs to change to make the IoT secure