security

  1. H

    How much do people trust Firewalla?

    Has anyone checked to see if they send anything home? Does anyone wonder if they have a backdoor into your router? Thanks
  2. J

    IPv6 DNS address

    If my router is set to “disable IPv6,” can I still point it to a DNS provider’s IPv6 address? And if I can, does this entail the same security downsides that allowing IPv6 more generally entails?
  3. J

    Brume 3 (GL-MT5000) High-Speed VPN Security Gateway

    Anybody have any experience using one of these? Thoughts? https://store-us.gl-inet.com/products/brume-3-gl-mt5000-high-speed-vpn-security-gateway
  4. T

    Incoming connection problem and ZenWifi Pro XT12 crash

    Hello everyone, I'm having an issue with one of my clients who uses a mesh network with an Asus ZenWifi Pro XT12 as their main router. It seems an incoming connection (IP address 45.227.253.13) is repeatedly attempting to connect remotely. This appears to be a bot attempt. The message in log is...
  5. P

    Security Problem on Asus RT-BE88U same on RT-AX88U Dual WAN Enabled

    Security Problem on Asus RT-BE88U same on RT-AX88U re Dual WAN Enabled - Running Merlin 3006.102.6 on RT-BE88U re below 4 screengrabs. Trend Micro Ai Protection is enabled and upon pressing the “Scan” button reports that all is secure. Now Enable Dual WAN at “WAN” > “Dual Wan” Tab – allow...
  6. lopperman

    After installing AdGuardHome, I noticed a few things that didn't seem right, here are my notes

    Disclaimer: I'm by no means a security expert, and I acknowledge that some of the issues I found after installing AdGuardHome could be caused by my own configuration mistakes, or might have nothing to do with AdGuardHome. I installed AdGuardHome today (version 1.9.3, via amtm). I'd been...
  7. Adamm

    Skynet Skynet v8 - Router Firewall & Security Enhancements

    📌 Skynet v8 - Router Firewall & Security Enhancements The largest upgrade in Skynet’s 11-year history Built exclusively for ASUSWRT-Merlin, Skynet v8 delivers a fully modernised codebase with major performance, reliability, and maintainability improvements - while keeping the familiar...
  8. A

    How secure is the Ai-Mesh backhaul channel?

    Per the title, how secure it she backhaul channel. I am setting up a pair of AX92U that are tri-band. 5ghz-2 to be the dedicated backhaul. * This is a sports scoring system that moves from venue to venue. * Purpose is to replace a hard wire that currently runs about 40 feet but typically...
  9. P

    [Security] SSH port opened to WAN even though "Enable SSH" is set to "LAN only"

    Today I run a port scan to my Asus RT-AX86U router running firmware 3004.388.9_2. To my surprise, I discovered that my SSH port is opened to WAN even though I have set it to "LAN only". Meaning, the "LAN only" setting is not in action at all! When I try SSH to my external IP address, the...
  10. T

    Critical Cache Poisoning Vulnerability in Dnsmasq

    Posting it here as I would like to understand if and how ASUS routers are affected, and if affected is there mitigation. Please move post as applicable. from https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2025q3/018288.html
  11. B

    How many connection attempts are you getting on your home router while all ports are closed?

    Hi, I'm getting 8 connection attempts per minute around the clock, or about 11500 per day. Is this normal? It seems a lot to me. What about you?
  12. I

    Latest CEVs regarding Asus routers, and what exactly is affected ?

    Hey all, I listen to the Security Now podcast, and on this week's Episode Steve mentioned a 9.8 rated CEV targeting Asus routers. I'll have to go back and listen to the podcast again once it posts, as I like to watch it live. What I'm curious about is, what all do these vulnerabilities affect...
  13. D

    Feature request: Two factor authentication web login. (TOTP)

    Merlin feature request: Two factor authentication web login. (TOTP - Time-based one-time password) I think this would benefit PAM (Pluggable Authentication Modules) authentication the routers use. For those that have no idea what I’m talking about it’s a security feature that requires you to...
  14. sfx2000

    Linksys Velop 6E, Velop Pro 7 - sending credentials to cloud in clear text

    This might be rather uncomfortable for the Linksys folks... Their SmartWifi solution is storing the WiFi credentials in plaintext up in their cloud servers... https://stackdiary.com/linksys-velop-routers-send-wi-fi-passwords-in-plaintext-to-us-servers/
  15. sfx2000

    CVE-2024-3094 - XZ Utils Backdoor - addtional info

    This had some traction over in AsusWRT-Addon's thread... I would post there, but the thread was closed. https://www.snbforums.com/threads/backdoor-in-linux-xz-utils-on-linux-distros.89469/ A couple of good write ups and analysis for this CVE are below...
  16. sfx2000

    This one is kind of interesting - Client and AP issues with WPA2/3

    Might have slipped below the radar - but Android and Routers have an issue here... https://www.top10vpn.com/research/wifi-vulnerabilities/ wpa_supplicant: CVE-2023-52160 IWD: CVE-2023-52161
  17. tonymet

    WPA2 Shared Secret Rotation: How to avoid downtime?

    Let's assume you like to rotate your WPA2 shared secret (SSID passphrase) once a year. How do you do it without downtime and with minimal fuss? Is it possible to do it without changing SSID? Here's how I do it: Start with existing SSID `wireless-net` Add new virtual SSID `wireless-net-A`...
  18. sfx2000

    getaddrinfo() on glibc calls getenv(), oh boy

    It's found on go, but this is something of interest to many... https://rachelbythebay.com/w/2023/10/16/env/ Be safe out there...
  19. Yota

    Plans to migrate to OpenSSL 3.0?

    The current firmware is using OpenSSL 1.1.1, which already ends support in September 2023. This means that it is no longer possible to get public security updates since last month. I still remember that it took about a year to migrate from OpenSSL 1.0.2 to 1.1.1 in 2019. I know there's so much...
  20. torstein

    How exactly do IoT smart devices pose a threat to home networks?

    I'm just curious, how exactly does a smart lock, or a light bulb or a smart kitchen appliance pose a threat? If you have your router properly set-up, disabled UPnP, enabled the firewall and no port forwarding, then there's no way some remote hacker can enter my home network through a security...
Back
Top