<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Bug report - Admin password length - EE Super Hub Plus in Broadband &amp; Landline</title>
    <link>https://community.ee.co.uk/t5/Broadband-Landline/Bug-report-Admin-password-length-EE-Super-Hub-Plus/m-p/1458439#M104391</link>
    <description>&lt;P&gt;&lt;a href="https://community.ee.co.uk/t5/user/viewprofilepage/user-id/3370209"&gt;@gergy008&lt;/a&gt;&amp;nbsp;Are you asking the forum as to why it's not been fixed?&lt;/P&gt;</description>
    <pubDate>Sat, 12 Oct 2024 15:16:49 GMT</pubDate>
    <dc:creator>JimM11</dc:creator>
    <dc:date>2024-10-12T15:16:49Z</dc:date>
    <item>
      <title>Bug report - Admin password length - EE Super Hub Plus</title>
      <link>https://community.ee.co.uk/t5/Broadband-Landline/Bug-report-Admin-password-length-EE-Super-Hub-Plus/m-p/1458380#M104377</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;I'm not sure how to submit a bug report with the router firmware that I found on the EE Super Hub Plus. So, I thought I would throw everything I know about the bug below. This might also make for a good bug reporting template.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Define the problem - What happened, and how can you trigger this again?&lt;/STRONG&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;Change administrator password text field allows more characters than the text field used to enter and change administrator settings. Change password to a long password, then try to enter it when changing settings. The field is limited so the password cannot be accepted.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What's the consequence?&lt;BR /&gt;&lt;/STRONG&gt;After changing the user password to a password longer than 20 characters, the user is then locked out and unable to access administrator controls.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;How is this resolved by a customer?&lt;BR /&gt;&lt;/STRONG&gt;Full router reset required to get the default admin password back, then the password can be changed to less or equal to 20 characters.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Is there a workaround?&lt;BR /&gt;&lt;/STRONG&gt;After changing password to more than 20 characters, a user &lt;EM&gt;can&lt;/EM&gt; use Inspect Element in the browser to manually change the maxlength attribute of the text field to accept more characters. The user can then log in just fine with the longer password.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Is this a potential security risk?&lt;/STRONG&gt;&lt;BR /&gt;Very low risk&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;If it is a potential security risk, how?&lt;/STRONG&gt;&lt;BR /&gt;Maximum password length is artificially and arbitrarily limited, making it easier for an agent to crack, or guess. The entire router interface, and the internal router software itself will accept a much longer password just fine.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What's the fix for the software developer?&lt;/STRONG&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;Review or remove requirement for max length via maxlength attribute used within password field of the confirm admin password modal.&lt;BR /&gt;&lt;BR /&gt;&lt;U&gt;DO NOT&lt;/U&gt; reduce the maxlength attribute value for the &lt;EM&gt;change&lt;/EM&gt; admin password screen, unless other technical reasons for reduction are present (otherwise a low security risk would remain present).&lt;BR /&gt;&lt;U&gt;DO NOT&lt;/U&gt;&amp;nbsp;truncate the user input (at any point) as this would introduce a new high security risk.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Oct 2024 13:08:15 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Broadband-Landline/Bug-report-Admin-password-length-EE-Super-Hub-Plus/m-p/1458380#M104377</guid>
      <dc:creator>gergy008</dc:creator>
      <dc:date>2024-10-12T13:08:15Z</dc:date>
    </item>
    <item>
      <title>Re: Bug report - Admin password length - EE Super Hub Plus</title>
      <link>https://community.ee.co.uk/t5/Broadband-Landline/Bug-report-Admin-password-length-EE-Super-Hub-Plus/m-p/1458384#M104379</link>
      <description>&lt;P&gt;This was previously raised in the following posts:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.ee.co.uk/t5/Broadband-Landline/Smart-Hub-Plus-password-length/td-p/1398871" target="_blank"&gt;https://community.ee.co.uk/t5/Broadband-Landline/Smart-Hub-Plus-password-length/td-p/1398871&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.ee.co.uk/t5/Broadband-Landline/New-security-password-not-accepted/td-p/1357838" target="_blank"&gt;https://community.ee.co.uk/t5/Broadband-Landline/New-security-password-not-accepted/td-p/1357838&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;This bug has existed for &lt;EM&gt;at least 8 months&lt;/EM&gt;, why hasn't this been fixed?&lt;/P&gt;</description>
      <pubDate>Sat, 12 Oct 2024 13:11:00 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Broadband-Landline/Bug-report-Admin-password-length-EE-Super-Hub-Plus/m-p/1458384#M104379</guid>
      <dc:creator>gergy008</dc:creator>
      <dc:date>2024-10-12T13:11:00Z</dc:date>
    </item>
    <item>
      <title>Re: Bug report - Admin password length - EE Super Hub Plus</title>
      <link>https://community.ee.co.uk/t5/Broadband-Landline/Bug-report-Admin-password-length-EE-Super-Hub-Plus/m-p/1458439#M104391</link>
      <description>&lt;P&gt;&lt;a href="https://community.ee.co.uk/t5/user/viewprofilepage/user-id/3370209"&gt;@gergy008&lt;/a&gt;&amp;nbsp;Are you asking the forum as to why it's not been fixed?&lt;/P&gt;</description>
      <pubDate>Sat, 12 Oct 2024 15:16:49 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Broadband-Landline/Bug-report-Admin-password-length-EE-Super-Hub-Plus/m-p/1458439#M104391</guid>
      <dc:creator>JimM11</dc:creator>
      <dc:date>2024-10-12T15:16:49Z</dc:date>
    </item>
    <item>
      <title>Re: Bug report - Admin password length - EE Super Hub Plus</title>
      <link>https://community.ee.co.uk/t5/Broadband-Landline/Bug-report-Admin-password-length-EE-Super-Hub-Plus/m-p/1459602#M104603</link>
      <description>&lt;P&gt;Good morning &lt;SPAN style="background: var(--ck-color-mention-background); color: var(--ck-color-mention-text);"&gt;&lt;a href="https://community.ee.co.uk/t5/user/viewprofilepage/user-id/3370209"&gt;@gergy008&lt;/a&gt;&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;Welcome to the EE Community, and thanks for taking the time to flag this too.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can certainly make sure we get this fed back, is it the latest EE Smart Hub Plus that you're referring to here?&lt;BR /&gt;Peter&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2024 09:49:23 GMT</pubDate>
      <guid>https://community.ee.co.uk/t5/Broadband-Landline/Bug-report-Admin-password-length-EE-Super-Hub-Plus/m-p/1459602#M104603</guid>
      <dc:creator>Peter_W</dc:creator>
      <dc:date>2024-10-15T09:49:23Z</dc:date>
    </item>
  </channel>
</rss>

