Yes i’m thinking about that, i see more as a feature than a security issue.

Let me explain, Three conditions must be met in order to upgrade:

  • There must be a host with the ip of the update server.
  • It must have a TFTP server.
  • It must have exactly the file name you are looking for.

If these three conditions are met … you know what you are doing, why should I stop you?

My question was more about whether there might be a conflict, but I’ve already seen that a problem was solved if there was a host with the ip of the update server but the TFTP server was not responding.

In any case, I’ll probably end up installing uboot-envtools and /etc/fw_env.config in our firmware to disable the auto-update once the process is finished.

Thanks.

1 Like