I know someone that is still running and OLD Linksys WRT45G router with default username and password. It dose not have remote access enabled and his ISP has him on CGNAT.
They will not replace it. No one will bother me……. Home use.
My question is, since they are on a CGNAT. how safe are they?
Mine was running great and still does actually.
I was so annoy the webinterface only allow 15 port forward, as some version firmware did not have the add +1 when you got at 15.
It became and still is a great DD-WRT router, with more than 15 port forwards.
Wendell mention it once somewhere it’s the line of defense for so many homes.
There is one way they can het breached fom outside, but will need a inside man to start a program to send UTP data outward. This open temporary ports outward on the CGNAT as it’s just natting, when executed with correct timing outside can send UTP back to the same port and take over the port.
This only work as it’s UTP, with TCP the firewall/NAT can detect is the flow reverses and close the port.
It called a UTP hole punch attack, and funnily overlay-VPN like Tailscail and Zerotier use the same attack with a relayserver coordinating to allow VPN clients on closed firewalls to set up connection.
So long story short you should be more worried about the strange guy in your house
Considering how utter shit is the security of new devices (see the threads about some ai assisted audits wendell did, or anybody else on youtube), it isnt that big of a difference.
CGNAT = relatively safe. At least compared to when the device was new. why?
the router not exposed to the big bad internet for inbound connections like it would have been originally
the device never pretended to do content inspection or anti-malware so that hasn’t degraded
because it doesn’t do content inspection, there’s no ancient code scanning content with a complex parser that could be compromised. so less chance of an outside influence breaking into the network that way, more likely an inside end user device being exploited to tunnel out.
so while its not great, its probably more secure than a more recent out of date router that does malware inspection but hasn’t had its scan engine updated and is full of shitty exploitable code.
the end devices behind it are on their own though. as they’ve always been. and as they are if they ever roam to a hostile network.