-- start quote
ASUSTeK Computer Inc (ASUS) have spent the better part of a year ignoring the fact that their RT-series routers suffer from two CRITICAL security vulnerabilities.
1. Default setting for the ftp-server was to allow anonymous login. ASUS calls this feature “limitless access rights”. We call this madness.
2. AiCloud usernames and passwords were stored in plaintext in a file available for download without logging in. We call this insanity.
This release includes
- IP-addresses to 12937 ASUS routers with vulnerable FTP and/or AiCloud.
- 6536 complete and 3605 partial lists of files shared from these ASUS routers.
- AiCloud login credentials to 3131 ASUS routers.
-- End quote
The story was removed from most sourced, but magnet-link containing IP and directory data are circulating on darknet sites like wildfire.
I'm afraid that many innocent victims are going to get hurt by this, and it all could have been avoided if the ISP's scanned their networks and warned their users.
I am at least trying to warn those i know have an ASUS Router, and so should you.