Categories: VoIP News

Warning: EdgeMarc Gateways and Session Border Controllers Passwords Could be Compromised

Our partner Bandwidth has alerted us that there is potentially a problem with the password security of EdgeMarc Gateways and Session Border Controllers (ESBC).

This might affect all EdgeMarc device owners. In short, the default Username / Password of “Root” / “Default” of these devices have been compromised.

However, if you changed your log in credentials when you programmed your EdgeMarc device then you are probably safe. If you were never prompted to change the default username / password you may not have thought to change it.

How to Tell If Your EdgeMarc Password Should be Changed and Steps to Take

From the Bandwidth announcement, here’s how to tell if you need to change your password and the steps to take:

If you are unsure if your specific device has been compromised, you can take the following steps to investigate. However, it is still highly recommended to change the password:

  • In the EdgeMarc GUI, under ‘System’ click on “Client List”. If there are any entries listed other than known and local IP addresses, there is a strong possibility that your device has been compromised. To resolve, remove the offending IP address.

Additionally, the following steps should be taken to to ensure a secure device:

  • Disable PPTP (Point-to-Point Protocol) – Under PPTP server > Username, ensure there is no user built unless it is a known user.
  • Disallow WAN clients – Under VoIP ALG, uncheck both the ‘allow clients on WAN’ option, as well as the ‘Enable LLDP’ option.
  • Verify no additional scripting has taken place, by looking under ‘User Commands’. Specifically, if the following script is present, it will need to be deleted:

ln -sf /etc /etc/images/m.txt
chmod 777 /etc/images/m.txt/config/passwd
sed -i -e s’_'”501″‘_'”0″‘_’ /etc/images/m.txt/config/passwd
sed -i -e s’_'”501″‘_'”0″‘_’ /etc/images/m.txt/config/passwd
sed -i -e s’_'”/etc/images”‘_'”/”‘_’ /etc/images/m.txt/config/passwd

Note: Some EdgeMarc screens within the GUI save changes while you’re making them, and others require you to hit a ‘submit’ button. Please take note of this while making your changes.

Need EdgeMarc Help?

Thank you to Bandwidth for bringing this problem to our attention.

If the above information did not help you and you still have concerns, please call us at 800-398-8647.

Nathan Miloszewski

Nate is VoIP Supply's former Content Marketing Manager.

Share
Published by
Nathan Miloszewski

Recent Posts

Watch Now: 2024 June VoIP News Update

https://youtu.be/JAvTUKqaquU?si=87UQ8WBKszoZIaBC Who's ready for their monthly dose of VoIP News? This month, we'll be covering…

4 days ago

How To: Choose the Right Outdoor Emergency Device with Enhanced Weather Protection

When selecting an outdoor emergency device, how do you know which features to consider that…

5 days ago

SIP Chats: Ryan Zoehner of Algo Solutions – New 8450 IP Console, Alyssa’s Law, and More!

https://www.youtube.com/watch?v=bDTEup-BRhw Our latest episode of SIP Chats is out now! In this episode, we're excited…

6 days ago

Q&A: Common Inquiries on Popular Yealink Products

Welcome to another helpful blog by VoIP Supply where we address common topics about popular…

1 week ago

Did You Know: 10 Reasons Why Your Business Should Switch to 3CX

It is essential to have an efficient and cost-effective communication system. 3CX is a unified…

2 weeks ago

Grandstream GWN7603 WiFi Access Point Product Feature Video

https://www.youtube.com/watch?v=XWCNjJ3xfIw Introducing the Grandstream GWN7603! This new addition to the GWN Series of WiFi access…

2 weeks ago