Ubiquiti EdgeRouters - vunerability

Ubiquiti EdgeRouters - vunerability

Author
Discussion

Brother D

Original Poster:

3,740 posts

177 months

Wednesday 28th February
quotequote all
I know a lot of people are very pro Unifi products on this forum (myself included) but this popped up in my feed just to make anyone that uses the edge routers aware.

https://duo.com/decipher/fbi-details-apt28-attacks...

(Probably not that many people use the edge routers but still its something to be aware of).


megaphone

10,769 posts

252 months

Wednesday 28th February
quotequote all
Brother D said:
I know a lot of people are very pro Unifi products on this forum (myself included) but this popped up in my feed just to make anyone that uses the edge routers aware.

https://duo.com/decipher/fbi-details-apt28-attacks...

(Probably not that many people use the edge routers but still its something to be aware of).
Thanks, I run a few Edgerouters and will keep an eye on any news. All are on the latest firmware, all have strong passwords.

outnumbered

4,099 posts

235 months

Wednesday 28th February
quotequote all

This is actually old news, and it was simply caused by Ubiquiti shipping devices with a default "admin" password. So the hackers didn't even have to try very hard.

As long as you've changed the default account/password to something unguessable, or turned off management access from the internet, there's no problem.

Brother D

Original Poster:

3,740 posts

177 months

Thursday 29th February
quotequote all
outnumbered said:
This is actually old news, and it was simply caused by Ubiquiti shipping devices with a default "admin" password. So the hackers didn't even have to try very hard.

As long as you've changed the default account/password to something unguessable, or turned off management access from the internet, there's no problem.
No... this is something new - the FBI released a notification last week regarding this:

https://www.justice.gov/opa/pr/justice-department-...


camel_landy

4,935 posts

184 months

Thursday 29th February
quotequote all
Brother D said:
No... this is something new - the FBI released a notification last week regarding this:

https://www.justice.gov/opa/pr/justice-department-...
Not really, it's still relying on default admin creds:

FBI said:
Non-GRU cybercriminals installed the Moobot malware on Ubiquiti Edge OS routers that still used publicly known default administrator passwords. GRU hackers then used the Moobot malware to install their own bespoke scripts and files that repurposed the botnet, turning it into a global cyber espionage platform.
M