Hacker News new | ask | show | jobs
by swinglock 1718 days ago
Indeed, the TL-SG105E/TL-SG108E is cheap because it's trash.

* The proprietary management interface listens to all VLANs no matter what.

* The VLAN separation is fake, multicast leaks freely across segments.

* The proprietary management protocol is obfuscated by a hard coded XOR string.

* Administrating the switch sends the admin password, "encrypted" only by the very same obfuscation.

* This most bizarre proprietary management protocol uses only broadcast for all communications, even though the switch has an IP assigned.

You do the math putting the above together... it's a mess bordering on genius, but there's more.

The switch will spew out various arcane, undocumented, probably providing more backdoors, not even IP protocols, including some Realtek proprietary protocol (0x8899), something used for HomePlug (0x893a) and TIPC (0x88ca), which sounds like the last thing you'd want a device of this caliber to use searching for more friends to talk to.

God knows what this monstrosity of a firmware hides and its reasons. It's just what I remember by heart, I have not had it powered up for some time. Still, this is just the surface and it's already a tire fire, it must be chock full of vulnerabilities, bugs and design flaws. It's the managed Ethernet switch which doesn't fulfill correct management nor implements actual Ethernet switching.

2 comments

Great... I just re-did my whole network with these.
Any other models you'd recommend that are more sane?
I have no idea, for all I know this could be better than other cheap switches, though I really hope not. The quality of home networking equipment and IoT in general is extremely low.