If you have a Genie DVR system, you should be aware of a major security flaw in the firmware that could allow a hacker to take complete control over the device.
At issue is the equipment offered by AT&T as part of their free DireTV WVB Kit. Researchers of the ZDI initiative and Trend Micro discovered a zero-day vulnerability in one of the core components of the system, Linksys WVBR0-25, which is a Linux-powered wireless video bridge. It is this bridge that allows customers to connect up to eight Genie client boxes connected to television sets in customers’ homes.
Trend Micro researcher Ricky Lawshae took a deep dive into the firmware and was able to get the Linksys WVBR0-25 to divulge a wealth of information from the device’s web server, without requiring any sort of authentication whatsoever. There wasn’t even a login screen, just a wall of easy-to-access text, which included:
Customer WPS PIN
Connected clients
Processes currently running
And more. Lawshae had this to say after completing his investigation:
“It literally took 30 seconds of looking at this device to find and verify an unauthenticated, remote root command injection vulnerability. It was at this point I became pretty frustrated.
The vendors involved here should have some form of secure development to prevent bugs like this from shipping. More than that, we as security practitioners have failed to affect the changes needed in the industry to prevent simple yet impactful bugs from reaching unsuspecting consumers.”
It gets worse, though. When the ZDI Initiative reported this security flaw to the manufacturer, rather than issuing a patch to correct it, they simply ceased all communication. After more than six months of trying, and getting nowhere, ZDI decided to publicize the vulnerability in the hopes that doing so would finally prompt the company to take action.
Until they do, about your only option (aside from simply canceling your service) is to limit the number of devices that can interact with Linksys WVBR0-25 so as to limit your exposure.
President & CEO
I hope you enjoyed this article. My mission is to take your stress away from dealing with IT problems. Call (252) 565-1235 or send me a message at our contact us page if you have a question, comment or want help.
What’s the next big thing for the PC world? If the industry’s major players have anything to say about it, it will be the “always-on” PC.

It feels as though every time you turn on the news, there’s a story about a company being hacked. If it’s happening to companies like Target and Adobe, then it could certainly happen to your company. That is why security and protection are key for having a successful business.
up appointment after the report of findings has been written and risks weighed. During this meeting, the pediatrician told me about the struggle she having with unimmunized children coming into the practice. She was very concerned about how to care for these children without putting her staff and other patients at risk. The pediatrician was very passionate about this subject and demonstrated a thorough understanding of how these non-vaccinated children were at risk themselves and putting others at risk.
the first place. Install a Domain Controller on the network to manage your data in a central place, the access your users have two that data, and be able to set automated complex password changes every 90 days.


Security researchers at UpGuard recently made a terrifying discovery in finding an unprotected Amazon S3 server containing several databases belonging to a data analytics provider called Alteryx.