Six million Sky broadband routers had major security flaw

25 November 2021, 13:34

Sky stock
Sky stock. Picture: PA

Security researchers said a software bug could have allowed hackers to take over a user’s home network.

Around six million Sky broadband routers contained a software bug that could have allowed hackers to take over home networks and access devices and personal data, a security company has said.

The flaw has been fixed, but the security researchers said it took the company nearly 18 months to fix the problem.

Sky said it took the security of its customers “very seriously” and had begun working to fix the problem as soon as it was made aware of it.

The bug, which was uncovered by the security group Pen Test Partners, affected users who had not changed the router’s default admin password – which was simple and easy to guess – and could enable hackers to easily reconfigure the router and take over a network just by directing the user to a malicious website.

This could then give hackers access to sensitive information including log-in details for online banking and other websites.

According to the researchers, the affected router models were: Sky Hub 3 (ER110), Sky Hub 3.5 (ER115), Booster 3 (EE120), Sky Hub (SR101), Sky Hub (SR203), and the Booster 4 (SE210).

In addition, around 1% of the routers issued by Sky are not made by the company itself and could not be updated with the fix.

But customers who have one can ask Sky to replace it, free of charge.

Pen Test Partners said there was no evidence the flaw had been exploited, but criticised Sky for the time it took to fix the issue.

It claimed the internet service provider had repeatedly pushed back deadlines it had set to fix the problem.

The researchers said they understood the initial delay due to the coronavirus lockdown and the challenges facing internet providers because of the “vastly increased network loading as working from home became the new norm”, which it said it did not want to disrupt.

But they said they were concerned by the overall speed of the company’s response, saying they believed Sky “did not give the patch the priority their customers deserved”.

The group also encouraged anyone with a broadband router to change the passwords on it from the ones set by default.

In response, a Sky spokesperson said: “We take the safety and security of our customers very seriously.

“After being alerted to the risk, we began work on finding a remedy for the problem and we can confirm that a fix has been delivered to all Sky manufactured products.”

By Press Association

More Technology News

See more More Technology News

The Pinwheel Watch, a smartwatch designed for children, unveiled at the CES technology show in Las Vegas.

CES 2025: Pinwheel launches child-friendly smartwatch with built in AI chatbot

The firm said the morning data jumps had emerged as part of its broadband network analysis (PA)

Millions head online at 6am, 7am and 8am as alarms go off, data shows

A mobile phone screen

Meta ends fact-checking on Facebook and Instagram in favour of community notes

Mark Zuckerberg

Meta criticised over ‘chilling’ content moderation changes

Apps displayed on smartphone

Swinney voices concern at Meta changes and will ‘keep considering’ use of X

sam altman

Sister of OpenAI CEO Sam Altman files lawsuit against brother alleging sexual abuse as child

OpenAI chief executive Sam Altman with then-prime minister Rishi Sunak at the AI Safety Summit in Milton Keynes in November 2023

OpenAI boss Sam Altman denies sister’s allegations of sexual abuse

A super-resolution prostate image

New prostate cancer imaging shows ‘extremely encouraging’ results in trials

Gadget Show

AI will help workers with their jobs, not replace them, tech executives say

Zuckerberg said he will "work with President Trump to push back on governments around the world that are going after American companies and pushing to censor more”.

Meta’s ‘chilling’ decision to ditch fact-checking and loosen moderation could have ‘dire consequences’ says charity

Twitter logo

X boss Linda Yaccarino praises Meta’s decision to scrap fact checkers

People walk by the Las Vegas Convention Centre

Smart home tech, AI and cars among central themes as CES 2025 prepares to open

An Apple phone

Apple to update AI tools after BBC complaint over inaccurate news alerts

Meta is ditching its fact-checking service

Meta ditches fact-checking on Facebook and Instagram in favour of X-style 'community notes'

A wallet with bank cards cash

35% of young adults ‘are concerned about their finances on a daily basis’

Broadcaster Cathy Newman at the Women of The Year Lunch and Awards 2019 in London

‘Haunting’ to see deepfake pornography of myself, says journalist Cathy Newman