EE promises to plug security hole found in Brightbox routers

EE logo
Brightbox found not so bright

EE needs to save its bacon, and we're not talking about a certain Footloose star.

The telco has embarked on a damage limitation exercise after a security researcher uncovered a vulnerability in its Brightbox home broadband routers that could let hackers make off with your private data.

Detailed in a blogpost by Scott Helme the flaw, which affects version 1 and 2 of the Brightbox, apparently makes it "incredibly easy" for hackers to gain administrator-level control using a Wi-Fi password.

Once inside, the attacker can easily access other personal information, such as account names and passwords.

EE, which has been shipping the routers since the beginning of 2012, has around 714,000 fixed line customers. Of those, it's been suggested that around 300,000 could be compromised.

Hook, line and sinker

Helme suggests that a hacker could even gather together enough information to cancel the victim's broadband subscription in order to run up hefty fees.

EE has come back at him to dispute this claim, however, telling the BBC that it would be impossible and that it has briefed its call centre workers to be extra vigilant to combat potential imposters.

The operator is working on a security fix for the flaw and promises that it will be delivered as soon as possible.

Latest in Security
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
ransomware avast
One of the most powerful ransomware hacks around has been cracked using some serious GPU power
person at a computer
Infamous ransomware hackers reveal new tool to brute-force VPNs
person at a computer
Many workers are overconfident at spotting phishing attacks
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft 365 accounts are under attack from new malware spoofing popular work apps
Data Breach
Thousands of healthcare records exposed online, including private patient information
Latest in News
Metroid Prime 4
I reckon the Nintendo Switch 2 could launch with Metroid Prime 4 – here’s why
Samsung Galaxy Z Fold 6
New rumors predict a foldable iPhone will launch next year – and cost almost twice as much as the iPhone 16 Pro Max
Pebble smartwatch countdown
Pebble confirms its smartwatch announcement is just hours away
Logo of YouTube Shorts
Is YouTube auto-playing Shorts when you open the app? Well, you’re not alone - here’s how to fix it
Google DeepMind panel discussion
“More sovereignty and protection” - Google goes all-in on UK AI with data residency, upskilling projects, and startup investments
Nintendo Switch 2
Nintendo Switch 2 expected to have AI upscaling and I can't wait to finally play Tears of the Kingdom with upgraded graphics