you are viewing a single comment's thread
view the rest of the comments
[–] 53 points 10 months ago* (1 child)

A few years ago I noticed an annoyance with a soundbar I had. After allowing it onto my WiFi network so we could stream music to it, it still broadcast the setup WiFi network.

While dorking around one day, I ran a port scan on my network and the soundbar reported port 22 (ssh) was open. I was able to log in as root and no password.
After a moment of “huh, that’s terrible security.” I connected to the (publicly open) setup network, ssh’d in, and copied the wpa_supplicant.conf file from the device to verify it had my WiFi info available to anyone with at least my mediocre skill level. I then factory reset the device, never to entrust it with any credentials again.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 18 points 10 months ago (1 child)

    Name and shame, what make and model was it?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 14 points 10 months ago* (1 child)

    It was a TCL Alto 9+.

    A quick internet search reveals that this issue was known about at least three years ago.

    Another model, the 8i was reported to have a root password of “12345678” - which is partially how I got the idea to start seeing if I could gain root.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 10 months ago

    TCL

    The Chinese company that steals corporate secrets (I kicked a bunch of their devs once when they were trying to take pictures of prototypes and copy source code on USB keys) and send everything to China? Who would have thought.

  • source
  • parent