• On TV.com: Dollhouse CANCELED, What Went Wrong?
October 20, 2009 2:45 PM PDT

Time Warner testing fix to hole in home router

by Elinor Mills
  • Font size
  • Print
  • 3 comments
Share

This is the SMC8014WG-S cable modem/Wi-Fi router provided to Time Warner cable customers that has a security hole.

(Credit: SMC)

Time Warner has rolled out a temporary patch and is testing a permanent fix for a security hole in a combination cable modem/Wi-Fi router that could allow anyone to access the private network of its customers, snoop on sensitive data, and direct customers to malicious Web sites.

The vulnerability in the SMC8014 cable modem/Wi-Fi router provided to customers was detailed in a blog post written by David Chen, a software engineer and co-founder of the Pip.io social communications platform start-up.

"We are aware of the issue and we are hard at work on a solution and have been for quite some time," Alex Dudley, a Time Warner Cable spokesman, said on Tuesday.

"The manufacturer has developed a fix," he added. "We believe it will work and we are testing it now to make sure it won't affect our network in other ways."

In the meantime, customers should be protected by a temporary patch, he said. Time Warner will push the permanent fix out to the affected devices from its regional data centers, possibly as soon as a matter of days, Dudley said.

About 67,000 devices across Time Warner's network are affected out of 14 million devices total, according to Dudley.

Chen wrote that he discovered that the administration features of the router had been disabled via JavaScript and that he was able to access all the features of the router by disabling JavaScript in the browser.

In addition, the device relied only on WEP encryption, which can be cracked easily, and it used a fixed format for the SSID (service set identifier), which makes it easy to tell which Wi-Fi network the device is using, he wrote.

"It just gets better from here. The extra features that I now had access to included a little item called 'Back Up Configuration File,'" Chen wrote. "When I clicked it, a text dump of the router's configurations was saved to my desktop. Upon examination of this file, I found the admin login & password in plaintext. Another issue which was alarming was the fact that by default, the web admin is accessible from ANYWHERE on the internet. By running a simple port scan of Time Warner IP addresses, I easily found dozens of these routers, open to attack."

Chen said he contacted Time Warner's security department and warned them about the security issue and that they weren't helpful at all.

Asked to comment, Dudley said: "Security is a primary concern and also a constant effort. So while we are currently working hard on ensuring this particular vulnerability is addressed as soon as possible, we are generally always working to improve and ensure the security of the network."

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
Recent posts from InSecurity Complex
Defense Dept. pulls software over privacy issues
Microsoft to plug critical IE hole targeted by exploit code
Avast update falsely flags good apps as malware
EFF sues feds for info on social-network surveillance
Fake CDC vaccine e-mail leads to malware
Building circuits, code, community at Noisebridge hacker space
Microsoft warns of IE exploit code in the wild
Chrome OS security: 'Sandboxing' and auto updates
Add a Comment (Log in or register) (3 Comments)
  • prev
  • 1
  • next
by techman21 October 20, 2009 3:55 PM PDT
There it is, I see it! The security hole is on the back under the letters "ETH"...and there's another one under "CATV"... Just kidding...
Reply to this comment
by libertyforall1776 October 21, 2009 2:05 PM PDT
WOW, complete and total incompetence...
Reply to this comment
by PSmith October 21, 2009 9:28 PM PDT
I'm a TW customer. I thank my lucky stars that I bought my own Wi-Fi router, rather than relying on their cr@p.
Reply to this comment
(3 Comments)
  • prev
  • 1
  • next
advertisement

The yogurt makers of tech: Gadgets to avoid

Don't buy these one-trick ponies--unless you like gizmos that gather dust.

Google wants to unclog Net's DNS plumbing

The Net giant, ever eager for a faster Internet, debuts its Google Public DNS service. With it, Google could become even more central to the Net.

About InSecurity Complex

Elinor Mills became fascinated with hacker culture when she was sent to Las Vegas to cover DefCon in 1995. Since then, script kiddies have given way to cyber criminals targeting bank passwords, and privacy risks are everywhere, from Google to Facebook and the iPhone. InSecurity Complex keeps tabs on the flaws, the foibles, and the fixes.

Add this feed to your online news reader

InSecurity Complex topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right