Security Experts:

Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Black Hat

China’s Huawei Responds to US Hackers

HONG KONG – (AFP) – Chinese communications giant Huawei Technologies on Wednesday responded to US hackers’ claims that its routers were easily cracked, saying its security strategies were rigorous.

HONG KONG – (AFP) – Chinese communications giant Huawei Technologies on Wednesday responded to US hackers’ claims that its routers were easily cracked, saying its security strategies were rigorous.

The annual Def Con hackers’ convention in Las Vegas on the weekend was shown how to slip into networks through some Huawei routers, which Recurity Labs chief Felix “FX” Lindner described as a “gift” to the hacker community.

Huawei Logo

Huawei routers, equipment that connects networks to the Internet, are widely used in Asia, Africa and the Middle East and the company has been striving to gain ground in US and European markets, according to Germany-based Recurity. 

Lindner and his teammate Gregor Kopf said they were troubled that Huawei had not issued security advisories about its routers to warn users to take precautions.

“These machines have serious security issues,” Kopf told AFP. “In my eyes, the greatest danger is that you don’t know how vulnerable it is; you’re left in the dark.”

Kopf said that once attackers slipped through the routers they could potentially run amok in networks.

In response, Huawei issued a statement to AFP saying it was aware of “media reports on security vulnerabilities in some small Huawei routers” and was trying to verify the claims.

“Huawei adopts rigorous security strategies and policies to protect the network security of our customers, and abides by industry standards and best practices in security risk and incident management,” it said.

The company said it had a “robust response system to address product security gaps and vulnerabilities”.

Huawei, founded by a former People’s Liberation Army engineer, has established itself as a major force in the global telecoms industry where its technology is widely used to build mobile phone networks.

But it is also battling an image problem in the broader technology market due to its perceived close ties with the Chinese state.

It has recently been blocked from bidding for contracts on Australia’s national broadband project, reportedly due to concerns about cyber-security.

The company has in the past also run afoul of US regulators and lawmakers because of worries over its links with the Chinese military — fears that Huawei has dismissed.

Related: China’s Huawei to Curb Business In Iran, Citing Increasingly Complex Environment

RelatedWho Watches the Watchers?

Written By

AFP 2023

Click to comment

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this webinar to learn best practices that organizations can use to improve both their resilience to new threats and their response times to incidents.

Register

Join this live webinar as we explore the potential security threats that can arise when third parties are granted access to a sensitive data or systems.

Register

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Identity & Access

Zero trust is not a replacement for identity and access management (IAM), but is the extension of IAM principles from people to everyone and...

Vulnerabilities

Apple has released updates for macOS, iOS and Safari and they all include a WebKit patch for a zero-day vulnerability tracked as CVE-2023-23529.

Network Security

NSA publishes guidance to help system administrators identify and mitigate cyber risks associated with transitioning to IPv6.

Application Security

Drupal released updates that resolve four vulnerabilities in Drupal core and three plugins.

Cyberwarfare

Websites of German airports, administration bodies and banks were hit by DDoS attacks attributed to Russian hacker group Killnet

Cloud Security

VMware vRealize Log Insight vulnerability allows an unauthenticated attacker to take full control of a target system.