J

Thursday, November 28th, 2024 12:40 AM

Expired Comodo CA Certificate on Admin Console

I have a rented CGM4331COM gateway and there seems to be an issue with the admin console's certificate chain.  Namely, the Comodo CA is expired, allowing the admin console to be accessible only via un-encrypted http, and not https.

This behavior is persistent even after a factory reset, and the gateway's firmware is up to date.  Is this a baseline condition of this specific gateway?

Our financial account information was recentley exfiltrated by bad actors, and I'm wondering if this expired cert was part of the attack chain.  Please advise.

Gold Problem Solver

 • 

26.1K Messages

16 days ago

... the admin console to be accessible only via un-encrypted http, and not https. ...

"https" is not needed. Please see https://forums.xfinity.com/conversations/your-home-network/10001-not-secure/673557ddf5a02920e72adc95?commentId=67356db90dda2449950869df.

Please be aware that there are 2 kinds of responses in this Forum: Replies and Comments. When you Comment on a post by scrolling down to "Comment on this post here...", I am notified of your response. But if you select Reply, I am NOT notified and may not be aware of your response.

(edited)

Official Employee

 • 

633 Messages

16 days ago

Good evening @jamesrexv. Could you please send our team a direct message with your full name and full address? Our team can most definitely take a further look at this issue.

 

To send a "Direct Message" ("Private") message:

Click "Sign In" if necessary

• Click the "Direct Message chat" icon

• Click the "New message" (pencil and paper) icon

• Type "Xfinity Support" in the "To:" line and select "Xfinity Support" from the drop-down list which appears. The "Xfinity Support" graphic replaces the "To:" line

• Type your message in the text area near the bottom of the window

• Press Enter to send it

forum icon

New to the Community?

Start Here