Yes sorry. I wasn't 100 percent. I believe I said Asian region in one of my post.
I've got the router operating after a wipe and refresh of the firmware and update.
Sent from my SM-G950U using Tapatalk
They got into the router, assigned their PPTP VPN, shut down my VPN and enabled AiDisk. They were after my 1TB attachment.
Luckily, AiDisk doesn't work in a multi-nat environment, so their effort wasn't fruitful.
Sent from my SM-G950U using Tapatalk
I need the router to be in operations again.
I am going to wipe and reload the firmware and update.
I will report back with any suspicious activities.
Thanks guys.
Outside of the firmware not being up to date, is there any way to confirm this isn't a vulnerability in the firmware that may not be patched as of today. Can I perform a system dump, if possible?
SSH, WAN ACCESSS were both off.
How can I determine how they gained access to the router?
Sent...
I didn't setup the PPTP VPN, not did I activate the AiDisk or the PPTP VPN.
Also when I looked at the services, ssh and WAN access is off.
So who gain access found a vulnerability in the firmware.
I'm going to contact the creator of Merlin to let him know. This has to be patched.
Sent...
Here is the syslog along with other photos of the current configurations.
https://drive.google.com/file/d/1C5pW4gJnWHj-7-i3xfAU2O4aaacFd2Or/view?usp=drivesdk
Sent from my SM-G950U using Tapatalk