ZTE's 4G hotspots said to lead to malicious sites

ZTEs 4G hotspots said to lead to malicious sites
The vulnerabilities are likely to apply to more ZTE products in the MF line.

San Francisco - In order to exploit vulnerabilities, an attacker only needed a victim to visit a malicious website using one of ZTE's hotspots



By IANS

Published: Sun 11 Aug 2019, 9:27 PM

Last updated: Sun 11 Aug 2019, 11:29 PM

Security researchers have discovered a bunch of vulnerabilities affecting 4G hotspots from Chinese handset maker ZTE that could allow a potential hacker to redirect traffic from the hotspot to other malicious websites.
Discovered by a Pen Test Partners researcher, who goes by the name of "Dave Null", the security flaws in the hotspot devices were disclosed at Defcon, an annual hacking conference held in Las Vegas, technology webiste CNET reported.
According to Null, in order to exploit the vulnerabilities, an attacker only needed the victim to visit a malicious website using one of ZTE's hotspots. Once the attacker had the password to the hotspot, there were plenty of options for further hacks possible.
The hacker could start logging a person's Web activity, use the hotspot as a way to attack devices connected to it and redirect Web traffic to more malicious websites, the report said.
Null claimed that the vulnerabilities are likely to apply to more ZTE products in the MF line because many of the devices share the same code, according to the report.


More news from TECH