During installation, the router sent several data packets to an Amazon server in the US. These packets contained the configured SSID name and password in clear text, as well as some identification tokens for this network within a broader database and an access token for a user session that could potentially enable a MITM attack.

Linksys has refused to acknowledge/respond to the issue.

  • @ikidd
    link
    English
    314 months ago

    Why are they sending that data to Cisco at all? That’s a ridiculous privacy violation, especially if they’re stupid enough to do it in cleartext.

    • @Hobo
      link
      English
      204 months ago

      You mean Linksys, not Cisco. Cisco sold Linksys to Belkin, now Foxconn, like over a decade ago. I think it’s a pretty important distinction considering Cisco is enterprise focused and linksys is more home/consumer focused.