Vulnerabilities Revealed in AT&T Modems

Vulnerabilities Revealed in AT&T Modems

Gaping security holes have been discovered in most AT&T U-verse cable modems that would allow remote cyber criminals to access a household’s internet connection as well as any devices connected to it.

Gaping security holes have been discovered in most AT&T U-verse cable modems that would allow remote cyber criminals to access a household’s internet connection as well as any devices connected to it, Infosec consulting firm Nomotion revealed in a new blog post.

According to the Register, the vulnerabilities cause potential harm to nearly 140,000 broadband modems.

“For those familiar with the technical history of Arris and their careless lingering of hardcoded accounts on their products, this report will sadly come as no surprise,” the Nomotion post said. “For everyone else, prepare to be horrified.”

Researchers said it is uncertain whether the security flaws were introduced by Arris, the company responsible for building the modems, or if they were added after delivery to AT&T – since their engineers have the ability to add and customize code running on the devices before putting them in customers’ hands.

The findings claim that the Arris modems carry hard-coded credentials which allowed a firmware update to turn on its Secure Shell (SSH) by default. This would allow a remote hacker to access the modem’s cshell service which includes capabilities such as “viewing/changing the WiFi SSID/password, modifying the network setup and re-flashing the firmware from a file served by any tftp server on the Internet.”

The specific modems which were found to contain the bugs are the Arris NVG589 and NVG599, which Nomotion said are provided as standard customer premises equipment for AT&T U-verse customers.

Technicalities of each of the five vulnerabilities are detailed in the post. It said the most prevalent and potentially dangerous vulnerability, based solely on the high number of affected devices, is a firewall bypass. Essentially, the only thing protecting an AT&T U-verse internal network device from the internet is whether or not a hacker knows or is able to “brute-force” the MAC address of any of its devices.

Nomotion hopes “that the problems will be swiftly patched and that going forward, peer reviews and/or vulnerability testing on new releases of production firmware will be implemented prior to pushing it to the gateways.” In the meantime, the post includes detailed instructions for various self-mitigation techniques that AT&T customers may use as workarounds for the vulnerabilities.

An Arris representative told Threatpost the company is verifying the details of the firm's report.

“Until this is complete, we cannot comment on its details,” Arris said in a statement to Threatpost. “We can confirm Arris is conducting a full investigation in parallel and will quickly take any required actions to protect the subscribers who use our devices.”

Featured

  • Security Industry Association Announces the 2026 Security Megatrends

    The Security Industry Association (SIA) has identified and forecasted the 2026 Security Megatrends, which form the basis of SIA’s signature annual Security Megatrends report defining the top 10 factors influencing both near- and long-term change in the global security industry. Read Now

  • The Future of Access Control: Cloud-Based Solutions for Safer Workplaces

    Access controls have revolutionized the way we protect our people, assets and operations. Gone are the days of cumbersome keychains and the security liabilities they introduced, but it’s a mistake to think that their evolution has reached its peak. Read Now

  • A Look at AI

    Large language models (LLMs) have taken the world by storm. Within months of OpenAI launching its AI chatbot, ChatGPT, it amassed more than 100 million users, making it the fastest-growing consumer application in history. Read Now

  • First, Do No Harm: Responsibly Applying Artificial Intelligence

    It was 2022 when early LLMs (Large Language Models) brought the term “AI” into mainstream public consciousness and since then, we’ve seen security corporations and integrators attempt to develop their solutions and sales pitches around the biggest tech boom of the 21st century. However, not all “artificial intelligence” is equally suitable for security applications, and it’s essential for end users to remain vigilant in understanding how their solutions are utilizing AI. Read Now

  • Improve Incident Response With Intelligent Cloud Video Surveillance

    Video surveillance is a vital part of business security, helping institutions protect against everyday threats for increased employee, customer, and student safety. However, many outdated surveillance solutions lack the ability to offer immediate insights into critical incidents. This slows down investigations and limits how effectively teams can respond to situations, creating greater risks for the organization. Read Now

New Products

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure.

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises.