2 thoughts on “Anytone AT-D878UV Encryption Vulnerability!

  1. New firmware update. Check out change number 5 below:

    D878UVII firmware update V3.03 (dated 2023-12-18) Change List
    1. Improve the scan speed, ignore some burst signal.
    2. Modify the SMS to support the Text Capture on BM.
    3. Modify the CPS to prohibit the CPS read the AES / ARC4 encryption from the radio, and prohibit the CPS read the AES / ARC4 encryption from the codeplug.
    To avoid the mistake, we suggest you do the process as below. 1. Save the codeplug in 3.02 CPS in .rdt file. 2. Do the firmware upgrade on the radio, and after firmware upgrade, the reset is a must. 3. Run the 3.03 CPS and open the saved .rdt file, the AES keys only display xxxx now, but it still works when write the code plug into radio. To be safe, engineer suggests you re-input the AES keys in the CPS before loading to radio, then it must work.
    4. CPS->Optional setting->Key function, add the β€œdim shut” function which allow set a key to shut off the radio backlight and LED completely.
    5. Modify the firmware to make the AES encryption have a variable Vector(IV) instead of fixed β€œ12345678”.

    Liked by 1 person

Leave a comment