Many vulnerabilities in older Huawei 3G routers will not be patched –
Although users are at risk, the devices are no longer technically supported by Huawei.
Huawei no longer plans to patch more than a dozen models of its older 3G routers, which have serious vulnerabilities. The bugs could allow an attacker to change DNS (Domain Name System) settings, upload new firmware without even logging into the device, and conduct a denial-of-service attack.
The affected router models, distributed in 21 countries, are now considered outside of Huawei's product family, and of course outside of its support, said Pierre Kim, the security researcher who found the security issues and listed the router models on his blog.
Router vulnerabilities can be exploited by attackers to redirect users to fake websites that appear legitimate, monitor web browsing , and a list of other offenses.
Kim's research focused on the Huawei B260a model, which was released by Tunisia Telecom. The same firmware, however, was used in a dozen other router models from the company, he said. The firmware he analyzed was last updated on February 20, 2013.
ISPs that distribute Huawei routers also modified the firmware to provide customized user interfaces, according to Kim. He also said he analyzed firmware for Huawei routers from different ISPs, and they all contained the same problems.
Kim found that the B260a model also stores the administrator name and password in cleartext in a cookie, which could be easily read by attackers. He also discovered that it was possible for someone to get the password for the router's Wi-Fi network without authentication.
[alert variation=”alert-info”]Note:
Anyone interested in further information can read Kim's research and get the list of routers by clicking herel[/alert]

