Second-hand enterprise routers still contain sensitive data, ESET finds

Share post:

ESET researchers have discovered that more than 50% of second-hand enterprise routers purchased for testing have not been wiped by their previous owners.

The routers, which included models by Cisco, Fortinet and Juniper Networks, contained confidential data, network information, and credentials that could easily be used to determine the previous owner. Among the data, were hashed root administrator passwords, VPN and secure network communication credentials, and router-to-router authentication keys. Moreover, eight of the routers contained data about connecting to other organizations’ networks, and two contained customer data.

Details on a corporation’s network operations and structure can be used for launching ransomware attacks, plotting espionage campaigns, and even identifying vulnerabilities in outdated software. ESET researchers say that the wealth of data on such devices would be highly valuable to cybercriminals and even state-backed hackers.

As in the ESET findings, Ford says that Red Balloon researchers have found passwords and other credentials and personally identifying information. Some data like usernames and configuration files are usually in plaintext and easily accessible, while passwords and configuration files are often protected because they are stored as scrambled cryptographic hashes. But Ford points out that even hashed data is still potentially at risk.

Since second-hand equipment is discounted, cybercriminals can purchase them and gain access to valuable information and network access. The researchers debated whether to release their findings or not, but they concluded that raising awareness about the issue is more important.

The sources for this piece include an article in ArsTechnica.

SUBSCRIBE NOW

Related articles

Hertz Data Breach Exposes Customer Information via Supply Chain Hack

Hertz has disclosed a data breach resulting from a cyberattack on its vendor, Cleo Communications, which compromised sensitive...

Google’s New Security Feature – Automatic Reboot

Google is introducing a new security feature in its latest Android update that will automatically reboot phones and...

Cybersecurity Firm Prodaft Buys Hacker Forum Accounts to Monitor Cybercriminal Activity

Swiss cybersecurity company Prodaft has initiated a program to purchase verified and aged accounts on hacking forums, aiming...

Operation Endgame: Burnaby, BC Resident Arrested As Cops Go After Individual Hackers

As part of Operation Endgame, international law enforcement agencies have arrested a Burnaby, British Columbia resident accused of...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways