The OpenWRT community forum behind the router firmware open source project was breached last weekend.
The data of users have been stolen which was just announced by the admin.
OpenWRT is an open source project that provides Linux distributions for embedded systems such as home routers. OpenWRT is therefore very commonly used in home routers. The project has its own forum to host its community.
Over the weekend, a hacker appears to have managed to breach it account of the administrator and perform decryption of user data. user. The hack posted on the forum.
On Saturday January 16, 2021, an unauthorized person hacked into an OpenWRT forum administrator account. The account was not protected by two-factor authentication. The attacker was able to extract a copy of the user list, including email addresses post officey, as well as other account data. At this time, it is unclear whether the attacker managed to copy the entire database. The forum administrators ask the users to reset the codes accessforum and change API keys (eg reset an OAuth key).