750-3.100-1217, unsecure firmware validation check

Thanks a lot, Leo. Thats looks now excellent for me.

On other point for possible improvements are the actual by gl used validation check for firmware by MD5.

It can be, it’s possible, to optimize the security in this point a little bit too from good to excellent, by replace the MD5 by sha256.

VBR

I have given this advice to the firmware development team, they will improve the side.

For some customers are, improving safety from Good to Excellent is an important argument for their purchase decision.

Thank you, Leo.

Addendum:
Is there already an approximate timetable ?
THX

Addendum:
Push up from the Easter Bunny

1 Like

Push up from end of April.
Thank you, Leo.
Is there already an approximate timetable ?
THX

I have urged relevant colleagues today, and there is no timetable yet. Thank you for your patience.

Today I discovered by chance a little How Too about the differences in the technical implementation of an integrity check by e.g. MD5 and SHA256, which is probably at least a partial solution for.

Just in case someone is interested in this for e.g. own projects. Experienced programmers, will surely know even more uncomplicated ways of implementation.

1 Like

Does it good news on father day about a more secure firmware update handling ?

A small partly how to:

1 Like

Now we have the half year jubilee of "unsecure-firmware-validation-check reporting on gl forum. Thats time for a party. Lets open champagne. :heart_eyes:

Ok. the bug report can be much older. Its not possible to check the bug reports from weeks of testing gl products, because the bug tracker was deleted:
GL.iNet - Connecting The World To Secure Wi-Fi :grimacing:

How ever. Today ist time for a party.
Looks forward.

There any news of fixing this security issue ?

THX

We conducted internal exchanges and discussions, and only optimized subsequent new products. (E.g. GL-X300B etc.)

Now for remembering the small partly how to for fixing this ooooooolllllllllllllld and easy to fix security issue:

The shareholder and the costumer will love the improvement of the products.

THX

Small remembering of unsecure firmware validation check security issue…

Full list of 3.104 test result can found on:

Looks like the firmware team are working on it since GL-MT1300
check the link below
https://dl.gl-inet.com/firmware/mt1300/testing/