It could be the worst router in the world: a cheapie from China that IOActive reckons is completely pwnable all ways from Sunday. Bought by a travelling staffer, Tao Sauvage, the BHU Wi-Fi router looks almost indistinguishable to a surveillance box. As Sauvage writes: “An unauthenticated attacker could bypass authentication, …

    What does the injected JavaScript do?

      The blog post linked to in the article does tell you more. However for the left-click challenged, the JavaScript file is loaded from a remote host; at the moment it's "just" a block of ads for other BHU products, but obviously that could change to be anything they wanted to make it.

    Obviously the company's name, BHU, is short for BHU-HA-HA-HA!

    That sounds like a very nice router. I would like to buy a bunch for use around here. It would make life so much easier.

    Buy a bunch, rebrand 'em and give 'em as gifts to your ex-clients who used to be really difficult...

    Or rebrand, hand a bunch of 'em out to IT security specialists as swag at a security conference...

    indistinguishable to a surveillance box

    "indistinguishable from" please

