Hacker News new | ask | show | jobs
by fragmede 1022 days ago
Even if you don't agree with it, the two lissues for the third point are that an RCE lets an attacker irreversibly modify the firmware remotely, or that the user will intentionally install an older unsupported version that contains an RCE. Vendor controlled firmware also has this issue, but that's the "compromises the security of everyone" with #3 because the attacker can now use the device as a VPN or as part of a DDOS botnet.