Zte Wifi Router Hack

Posted on  by 

A security vulnerability has been found in Brit broadband biz Hyperoptic's home routers that exposes tens of thousands of its subscribers to hackers.

The gigabit provider's routers are made by ZTE, the Chinese electronics giant that American and British spy agencies have sounded an alarm over. The United States has also imposed a ban on American companies selling components to ZTE and other Chinese network gear makers.

Zte Wifi Router Hacked

In November, infosec outfit Context IS alerted consumer-rights charity Which? to critical vulnerabilities found in the Hyperoptic broadband home router H298N. These bugs can be exploited to gain control of the device, change its firewall and security settings, change the administrative password, and generally cause havoc.

All a victim has to do is click on a link, for example in an email or message, while on the same local network as the router, to trigger exploitation: the URL takes the victim to a webpage that abuses a hardcoded root password in the router.

ZTE Wireless Internet Router IFWA 40 Mobile 4g lte Wifi Hotspot IFWA 40 antenna AT&T 4g lte WiFi Connect Up to 20 Devices Create A WLAN Anywhere GSM (Renewed) 3.9 out of 5 stars 11 $139.99 $ 139.

'The combination of a hardcoded root account and a DNS rebinding vulnerability allows an internet-based attacker to compromise all customer routers of UK ISP Hyperoptic via a malicious webpage,' Context IS said in an advisory on Tuesday. 'The vulnerabilities are present on both “HyperHub” router models, the ZTE H298N and the newer ZTE H298A, affecting hundreds of thousands of devices.'

Find zte router passwords and usernames using this router password list for zte routers. To access the zte router admin console of your device, just follow this article. Below is list of all the username and password combinations that we are aware of for zte routers. The team then tested a separate ZTE device (MF920), finding 'almost the exact same issues.' The vulnerability on the newer device has been fixed, but the researchers believe this shows that ZTE is.

By hijacking the routers, attackers could also turn them into a part of a powerful botnet, given Hyperoptic's speeds of up to 1Gbps.

According to the Which? article more than 400,000 customers may have been affected. However, as pointed out by ISP Review, the actual subscriber figure is more likely to be closer to 100,000.

Daniel Cater, the security researcher at Context IS who discovered the flaw, said: “This has implications for the customers’ own data, but also if an attacker compromises enough routers of an ISP, the threat is elevated and has the potential to impact national security, such as via mass surveillance or DDoS attacks against critical infrastructure.

“Recent announcements from the [National Cyber Security Centre] have shown that attacks such as this against other ISPs and routers are not hypothetical. All ISPs should take this seriously, and invest in thoroughly testing their consumer devices and their infrastructure if they are not already doing so.”

Hyperoptic secured all its ZTE routers in December 2017 once it was alerted to the problem, said a spokeswoman. It then rolled out a more permanent fix, upgrading the firmware in all customer routers in April 2018. The fix was to basically set individual root passwords for the devices.

She said: 'We have no evidence nor reports of any customers affected, and all customer routers are now secured against it.'

Separate research from Broadband Genie found as many as 82 per cent of punters have never changed the password and security setting on their routers. ®

Get ourTech Resources

This is a complete list of user names and passwords for ZTE routers.

How To Login to a ZTE Router

Most routers have a web interface. This means that in order to login to them you start with your web browser.

In general you login to a ZTE router in three steps:

  1. Enter Your ZTE Router IP Address Into your web browser's Address Bar
  2. Enter your ZTE Router username and password when prompted
Wifi

The list of user names and passwords is below.

How to Reset Your ZTE Router Password To Default Settings

If none of the passwords below work for you then you have 2 options:

  • Either try to recover your router's password with Network Utilities Find Password
  • Or Reset your ZTE router

Zte Wifi Router Hacks

Please only reset your router as a last resort.

ZTE Router Password List

Here is a list of all known ZTE passwords and the router they were discovered on.

Be sure to try them all!

ZTE ModelUsernamePassword
AC30adminadmin
AR550adminadmin
Bavo ZXV10-W300adminadmin
DNA Mokkula 4G MF920Vblank1234
F609adminadmin
F612Wadminadmin
F620adminadmin
F660adminadmin
F660useruser
F668adminadmin
F668adminpassword
F670adminadmin
F670useruser
H220NHPNblank
H220NKPNblank
H268Aadminadmin
H268Auseruser
H368Nadminadmin
H369Auseruser
IX380 Wateenadminadmin
IX380 Wateenuseruser
MF275Rblankadmin
MF279blankattadmin
MF279Tblankadmin
MF283blank1234
MF283blankadmin
MF283Vblankadmin
MF286blanksame as default wifi, printed on router
MF28Bblankblank
MF28Bblankblank
MF29Ablankadmin
MF368 MTNmtnadmin
MF612adminadmin
MF65blanksmartbro
MF65Mblankadmin
MF90adminadmin
MF910adminadmin
MF910blankpassword
MF910Vadminadmin
MF910Vblankpassword
MF920Vadminadmin
MF923blankattadmin
MF93Dadminadmin
MF975S Sprintblankpassword
NetFasteR WLANadminadmin
Speedport Entry 2iadminon router label
Z-917blankadmin
Z288Ladminprinted on router
Z700Ablankattadmin
ZXDSL 531Badminadmin
ZXDSL 831CIIadminadmin
ZXDSL 831DZXDSLZXDSL
ZXDSL 931VIIadminadmin
ZXDSL 931VII Netvigatoruseruser
ZXDSL 931VII T-Mobile3play3play
ZXDSL-831AIIadminadmin
ZXHN F609adminadmin
ZXHN F620adminadmin
ZXHN H108Ladminadmin
ZXHN H108Nadminadmin
ZXHN H108Nuserblank
ZXHN H108N Bayanadminbayandsl
ZXHN H108N Telkomadminadmin
ZXHN H108N v2 TE Dataadminadmin
ZXHN H108N v2.5useruser
ZXHN H118N Vivacomuseruser
ZXHN H168Nadminunknown
ZXHN H168Nuserblank
ZXHN H198A v3.0adminaisadmin
ZXHN H208Nadminadmin
ZXHN H208Ncytausercytauser
ZXHN H267Acytausercytauser
ZXHN H267Atmadmintmadmin
ZXHN H267A v1.0adminsuperonline
ZXHN H267Nadminadmin
ZXHN H267N Cytacytausercytauser
ZXHN H268Aadminadmin
ZXHN H298Nadminpassword
ZXHN H298Nlocated on the back of the routerlocated on the back of the router
ZXHN H298Nuseruser
ZXHN H367A v1.012341234
ZXHN H367Nadminadmin
ZXHN H368Cadminadmin
ZXV10 H201Ladminadmin
ZXV10 H208Ladminadmin
ZXV10 W300adminadmin

Coments are closed