Attackers can easily gain administrators rights on ADSL modem routers of Asus and ZTE because they use a hard-coded password based on the MAC address, according to the CERT Coordination Center (CERT/CC) of the Carnegie Mellon University.

CERT/CC warns that the hard-coded password allows attackers to start a Telnet session to the device and then take full control by gaining administrator rights. The affected routers, which besides Asus and ZTE also include modems of Observa Telecom, Speedsurf and Philippine Long Distance Telecom, have passwords based on the MAC address. The MAC address can be easily found using the Simple Network Management Protocol (SNMP).
According to CERT/CC there is currently no practical solution to the problem and therefore recommends to restrict access to untrusted sources and to enable firewall rules that block SNMP on the device.
To check if your ADSL modem/router is vulnerable, check the CERT/CC page here.















