chr = lowest security

if the manufacturer thought about security, there would be no empty password and an active interface when deploying a cloud image. how you can run such an image in the cloud with such settings is not clear at all. Have you studied at least the customer usage scenario ? do you understand that everyone always has VPS/VDI with open ports and interfaces? it was possible to change the password and enable the network interface only through the locale.

open telnet and admin without password in 2021 - laughter

Just secure your CHR instance as you need immediately after deployment.

I guess it’s not as bad in 2022. :sweat_smile:

@gabacho4/@ns88ns: it’s like any other business router that you need to configure before deploying. The same goes for Cisco, Juniper, etc. It’s not really “best practice” to deploy a solution before it is fully configured. In the case of CHR, for example, use the internal v-switch for configuration.

Also, most professionals use sandboxed environments to simulate access which are available in most clouds or use GNS3/EVE-NG (or sometimes a combination of both)

A consumer router is a total different matter…

A brand new cisco router out of the box has no password either.

In Azure I do not add public IP when I deploy the image and using the serial consol to set up the must have security settings and add Public IP later.

Pretty basic, I would say ?
I know in some parts of the world it’s a bit different but in Belgium, all houses have a front/back door which is always locked (should be, you can even get a fine when you leave it open since that would potentially invite burglars).
You don’t move in your furniture or personal stuff without making sure that door can be locked.

Same thing needs to be done on a router. First get your initial setup in order before using it in the Big Bad World.

The concept is even simpler:
You “simply” prepare the disk image as you please before uploading it to the cloud.
What’s the problem?

@Samosval
If one does the opposite, what do you expect?

“There are no insecure settings, there are just people ignorant of how to use them all together.”
(Rex, 2022)