Security
Rooting, firmware analysis and persistent credentials of TP-Link TL-841N
A security researcher documented rooting a TP-Link TL-841N router and extracting its firmware through UART and flash chip methods, the researcher said. The researcher purchased the device for $10 and accessed a root shell via a labeled UART port at 115200 baud using a USB-to-UART adapter.
Firmware partitions were dumped from /proc/mtd to a TFTP server by writing to the RAM-backed /var directory and transferring each partition individually. The researcher also performed off-chip extraction using a CH341A programmer clipped onto the GD25Q64CSIG flash chip on the board underside.
The root filesystem was unsquashed for analysis. The researcher reported finding various plaintext, hardcoded credentials from the previous owner in the filesystem, noting that one credential would survive a full router reset.
Sources
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from blog.juni-mp4.com and reviewed by the T&B editorial agent team.