Backdoors and many other vulnerabilities have been discovered in the firmware of a popular FiberHome FTTH ONT router. FTTH ONT stands for Fiber-to-the-Home Optical Network Terminal and are special devices placed at the end of fiber optic cables. Their role is to convert optical signals sent over fiber optic cables into classic Ethernet or wireless (Wi-Fi) connections.

FTTH ONT routers are usually installed in apartment buildings or inside homes or businesses that opt for gigabit subscriptions.
In a report published last week, security researcher Pierre Kim said he identified a large collection of security issues in the FiberHome HG6245D and FiberHome RP2602, two FTTH ONT router models developed by Chinese company FiberHome Networks.
The report describes both the positive and negative issues of the two router models and their firmware.
For example, the positive aspects are that both devices do not expose the management panel via the external IPv4 interface, making it impossible to attack the web panel via the internet. In addition, the Telnet management feature, which is often used by botnets, is also disabled by default.
However, Kim says that FiberHome engineers apparently failed to enable these protection features on the routers' IPv6 interface. Kim notes that the device's firewall is only active on the IPv4 interface and not on IPv6, allowing threat actors to have direct access to all of the router's internal services as long as they know the IPv6 address .
Kim described several backdoors and vulnerabilities he discovered on the device, which he claims attackers could exploit to take over ISP infrastructure.
Based on the number and nature of backdoors he discovered within the device, Kim said he believes "that some backdoors have been intentionally placed by the company."
Kim said he found these issues in January 2020 and immediately notified the company. The researcher was unable to determine whether the bugs as he has not tested newer versions of the firmware since then.
Furthermore, the researcher also warns that the same backdoors or vulnerabilities could also affect other FiberHome models due to the fact that most vendors tend to reuse or slightly modify firmware between different production runs.
It is extremely urgent to protect FiberHome routers. In late 2019, security researchers at Qihoo 360 reported that threat actors had already abused FiberHome systems to assemble botnets, which are used as proxies.
In May 2020, the US Department of Commerce added FiberHome and eight other Chinese technology companies to a blacklist that restricts their access to American companies.
Information source: zdnet.com
