Skip to content

Hacking Hotspots: Pre-Auth Remote Code Execution, Arbitrary SMS & Adjacent Attacks on 5G & 4G/LTE Routers

Notifications You must be signed in to change notification settings

actuator/DEFCON-33

Repository files navigation

Overview

image

Materials and references for my DEF CON 33 talk on exploiting vulnerabilities in Tuoshi and Kuwfi 5G & LTE Routers.

Covers CVE discoveries, exploitation demos, and lessons learned from vendor analysis.


Agenda

  1. Whoami
  2. Related Work
  3. Tuoshi Devices
  4. Kuwfi Devices
  5. Conclusions

Highlights


Devices

Tuoshi (Dionlink): NR500-EA, LT15D, LT21B

Kuwfi: GC111, AC900, CPF908, 5G01-X55

About

Hacking Hotspots: Pre-Auth Remote Code Execution, Arbitrary SMS & Adjacent Attacks on 5G & 4G/LTE Routers

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published