This talk tells the story of how a routine penetration test of one day became a months long solo journey into uncovering six zero day vulnerabilities in a home ONT router used all over the world, but especially across the American continent, including the United States, Canada, Argentina, Mexico, Brazil, and Ecuador.
In 2025, I was hired by an Ecuadorian entity after an ISP detected suspicious activity impacting its own infrastructure, potentially originating from users of these routers. They needed to understand what was happening. What began as a standard assessment quickly went far beyond typical testing. Instead of stopping at network level analysis with a port scan and check vulnerable services, I moved deeper into hardware hacking and firmware reverse engineering. What I found was unexpected. A massively deployed router with no prior CVEs!!!. That absence was not reassuring, it was suspicious. Working completely alone, I faced significant technical challenges, including reversing firmware built on the uncommon ARCompact architecture. Step by step, this led to the discovery of five zero day vulnerabilities.
At that point, I was facing a difficult situation. The vendor initially refused to patch the vulnerabilities, even though there were around 60,000 of these end of life routers still in use just in one of the affected countries and many more deployed worldwide. Given the scale and urgency, I briefly considered turning to the black market as a way to force attention to the issue. However, I ultimately chose responsible disclosure instead (but I discovered a big black market about zero days in routers). What followed was a difficult, months long process with the vendor that eventually resulted in five CVEs and the patch in 2025. To make progress, I had to adopt a more assertive, hacktivist style approach with the vendor after their initial refusal to address the flaws (the timeline is quite emotional!).
In March 2026, after I published the CVEs in my blog, an anonymous hacker contacted me. He had read my work and revealed something unexpected. He was the author of a sixth zero day vulnerability affecting the same routers, one I had previously come across without knowing its origin. What started as an individual effort suddenly connected to a hidden parallel discovery (in total 6 zero days were in the underground/undiscovered for more than 10 years)
In March 20, 2026, I verified the vulnerability and conducted a global reassessment of these routers. The results are quite interesting. These devices are already end of life, yet they are still being used all over the world, with official support extended until 2027/2028. The message: EOL routers are very serious risk!"
Presented at Ekoparty Miami 2026