During installation, the router sent several data packets to an Amazon server in the US. These packets contained the configured SSID name and password in clear text, as well as some identification tokens for this network within a broader database and an access token for a user session that could potentially enable a MITM attack.

Linksys has refused to acknowledge/respond to the issue.

  • @ikidd
    link
    English
    14 months ago

    I thought Ubiquiti moved back to cloud managed on everything? Or is that just the network cameras?

    • yeehaw
      link
      fedilink
      English
      14 months ago

      Not sure, been a while since I used those