SLASHDOTTED! Hacking the Free “La Fonera” Wireless Router
Oh no! Could this be the counter-revolution we have feared?
Despite efforts to keep La Fonera (which we affectionately call “El Cheapo”) secured against firmware reflashing, it appears that it can be done without opening it up or building special hardware!
Visit these links to evaluate the grim evidence:
http://hardware.slashdot.org/hardware/06/11/05/1919220.shtml
http://fonblog.wordpress.com/2006/11/05/a-ssh-access-to-la-fonera-without-phisical-hack/
http://stefans.datenbruch.de/lafonera/
http://www.pobletewireless.es.mw/
ADDITION: Nov 6: Martin Varsavsky, in his Spanish version of his blog only, acknowleges the script weakness and states that it has been patched:
http://spanish.martinvarsavsky.net/fon/hackers-bugs-y-fon.html
ADDITION: Nov 8: Dema writes that there are reports that script weakness appears to have stopped working:
http://fonblog.wordpress.com/2006/11/08/fon-patched-the-injection-code-vulnerability/