Jason
Share your feedback through our survey, make your voice heard, and win a
WiFi 7 AP! https://bit.ly/2024_Survey_Community
IMPORTANT - tenanted leakage
FrankIversen
Posts: 92 Ally Member
Hi.
We just registered a new switch to a customer. we get an erorr in the nebula app saying "this device is already registered".
So we chose "great, yes, do that" and press OK. Then a switch, which is online, is showing up. it is not our switch. We get all the information on the swtich (ports used, mac/ips etc.) and we can see the public wan. the public wan adress points to an unknown ip-adresse in our country.
We try to register the switch again, this time from the qr-code on the switch itselfes, not on the box. then it works.
Now we have 2 devices. On is our regular switch, the other switch is the another company.......
I suggest you contact me directly for showing you the details. We will have to fill a blanket for a GDPR situation here.
We just registered a new switch to a customer. we get an erorr in the nebula app saying "this device is already registered".
So we chose "great, yes, do that" and press OK. Then a switch, which is online, is showing up. it is not our switch. We get all the information on the swtich (ports used, mac/ips etc.) and we can see the public wan. the public wan adress points to an unknown ip-adresse in our country.
We try to register the switch again, this time from the qr-code on the switch itselfes, not on the box. then it works.
Now we have 2 devices. On is our regular switch, the other switch is the another company.......
I suggest you contact me directly for showing you the details. We will have to fill a blanket for a GDPR situation here.
0
All Replies
-
we have also created a more detailed ticket on partnersupport@zyxel.se with #158081 Please check the information we have provided there.
Thanks.0 -
Hi @FrankIversen ,
Thanks for your feedback.
I will PM you for the following detail information for this case, so we can check the logs on our server.- MAC address and S/N number of the Switches.
- The picture of the QR-code
- The organization/site name which the Switch is registered to now.
Kindly check your Inbox later.
0 -
Hi @FrankIversen ,
We find that there is a mismatch between QR-code and MAC/SN sticker of your Switch brown box.
We are now working on it.
Sorry for your inconvenience.
Jason
Share your feedback through our survey, make your voice heard, and win a WiFi 7 AP! https://bit.ly/2024_Survey_Community0 -
the mismatch is one thing. but the ability to transwer a switch from a tenant we do not control is not good at all. that is a big securityhole.0
-
Hi @FrankIversen ,
First of all, sorry to make you confused and thanks your feedback to have this security concern.
The feature "User can scan QR-code on the Nebula device via Nebula APP to register to his/her organization/site directly" is based on the motivation below.
Motivation:
To let the second-hand device can be faster and more convenient to be registered by the new user if the previous user didn't unregister from his/her organization.
Why is QR-code?
We make this mechanism on "Scanning device QR-code via Nebula APP" because we think it can prove the Nebula device is actually on the new user's hand.
For this case, there is indeed something wrong at the rework process for your device, so it causes the QR-code is mismatch.
Jason
Share your feedback through our survey, make your voice heard, and win a WiFi 7 AP! https://bit.ly/2024_Survey_Community0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 144 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.6K Security
- 237 USG FLEX H Series
- 267 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.3K Consumer Product
- 247 Service & License
- 384 News and Release
- 83 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight