Hi there
We had the notification on our XG 210 to say that it was Partially Cleaned (ie compromised) etc.
The User Portal is disabled on WAN, never used it.
The Admin Portal is enabled on WAN, but access is restricted to our head office trusted IP only. It's not usually something I would ever enable, but the device sits in a secure datacentre and remote access is essential.
I've seen a lot of people here ask a similar question, but nobody has given an actual answer.
How can the device be potentially compromised if it's only accessible from one trusted IP? This restriction DOES work by the way, I have tested thoroughly.
The admin portal login page doesn't even appear for anyone to carry out a SQL injection attack... anyone enlighten me?
Thanks!
This thread was automatically locked due to age.