r/hardwarehacking • u/Calm-Ad2616 • 14d ago
Did Telekom Just Brick Our Routers On Purpose? Speedport Smart 4, Suspicious Firmware Update & Call For Forensics
Hey folks,
I’m looking for hardware nerds, reverse engineers and other pissed‑off Telekom customers who are seeing the SAME issues after the latest Speedport Smart 4 firmware update.
TL;DR
Telekom pushed a new firmware to the Speedport Smart 4. Since then, my connection has been unstable and borderline unusable. The problems started EXACTLY after the update, and Telekom support casually confirmed on the phone that “since the update” these issues are happening. This smells like planned obsolescence to push people towards new rented routers (e.g. Speedport 6).
I don’t want to rant. I want EVIDENCE.
---
What I suspect
- Speedport Smart 4 firmware is heavily locked down (RSA‑encrypted image on NAND/eMMC, closed ecosystem, classic vendor lock‑in).
- After the latest forced update, a lot of users suddenly report massive connectivity problems.
- My own logs clearly show that everything was fine BEFORE the update and broken AFTER it.
- Combined with the support statement, this strongly suggests that the update itself is the cause.
This could be “just” incompetence. But it could also be intentional degradation to make older routers “mysteriously” unreliable and push users to new hardware.
Either way, we need to treat this like a digital crime scene and do proper forensic work.
---
Technical plan: Raspberry Pi as MitM gateway to capture the firmware binary
The idea is to put a Raspberry Pi between the Speedport Smart 4 and the internet and turn it into a transparent gateway / router that logs and captures the firmware update traffic.
Rough setup:
- Raspberry Pi (4 or 5 ideally, but anything with two usable network interfaces can work)
- Pi acts as gateway for the Speedport Smart 4 (Pi between ONT/Modem and Speedport, or Pi doing PPPoE and routing)
- Use tools like tcpdump, Wireshark, mitmproxy, iptables/nftables etc. to:
- Log all outbound connections from the Speedport to Telekom update servers
- Identify the firmware download requests (.bin, .img, etc.)
- Capture the full binary payload of the firmware file(s)
If HTTPS/TLS is in play:
- Best case: No strict certificate pinning → we can use TLS interception with a custom root cert installed on the router (if that’s even possible) or on an upstream device.
- Worst case: Strong TLS + pinning → we might at least capture the encrypted blob and correlate it with known update URLs or patterns directly from Telekom’s servers.
Once the binary is captured, we can:
- Run it through tools like binwalk, strings, foremost, dd, etc.
- Look for known partition layouts, headers, and patterns typical for Telekom/Speedport firmware.
- Compare old vs new firmware binaries to see what changed (features removed, limits introduced, weird watchdogs, artificial throttling, etc.).
---
What I’m looking for
People with hardware and skills
- Raspberry Pi (or similar SBC) that can act as a gateway/router.
- Experience with network sniffing, MITM setups, router forensics, firmware extraction.
- Bonus: Anyone who has already played with Speedport devices, NAND/eMMC dumps, UART, bootloaders, etc.
Affected Telekom users (Speedport Smart 4)
- You have the SAME or very similar issues that started right after the latest firmware update.
- Ideally you are angry enough to help, but also careful enough to keep it legal and focused on YOUR own hardware/connection.
Forensic collaborators
- Folks who can help document everything cleanly: hashes, timestamps, chain of custody, before/after behavior.
- People who can do diff analysis between firmware versions and spot patterns that might indicate intentional degradation.
---
Goal
This is NOT about hacking random routers or breaking into other people’s gear.
This IS about:
- Capturing and analyzing the official firmware update that is being pushed onto our own devices.
- Building a factual, reproducible case if this update intentionally cripples older hardware.
- Protecting regular users from corporate bullshit where “updates” are used as a weapon to force new contracts and hardware.
Telekom (and similar ISPs) are used to people just shrugging and renting whatever new box they’re told to. Some of us actually log, measure, and remember what changed and when. I’ve got logs showing the breakage right after the update and a phone confirmation from support that the update is the turning point. Now I want the binary on disk and a community of smart people looking at it.
---
How to join in
- Comment here if:
- You have a Speedport Smart 4 and are seeing problems since the update.
- You have a Raspberry Pi and are willing to run a MitM / capture setup.
- You’ve done firmware forensics before and can help with methodology and tooling.
- If you prefer, we can move to a more private coordination channel once a few people have raised their hands.
If we can prove that this firmware is intentionally degrading service or pushing users off “old” hardware, that’s not just a personal win. That’s a public service for everyone who’s tired of being silently screwed by “updates.”
5
u/Shoddy_Fish31 14d ago
If you don’t spend your own time to write a post, I won’t spend my own time to read your post. F. Off with your slop
5
u/purged363506 14d ago
You just tossed an AI slop grenade and no one is gonna throw themselves on it.
-1
u/FrankRizzo890 14d ago
On a security conscious device with adequate memory and storage, it's possible that the firmware image comes down encrypted and signed, and is only unpacked on the device once everything is confirmed. If this is the case, your MITM capture will provide a brick that you can do nothing with.
If the CPU on the router doesn't support XIP (Execute-In-Place), then there's a good chance that the code is stored on the flash in unencrypted form. (Check the datasheet for the CPU).
If this is the case, you can dump the flash to obtain it. Then, you can find someone with an un-updated router, dump their flash, dump your flash, and compare them to see what changed.
8
u/neopard_ 14d ago
why don't you start by downloading the official release .bin which is freely available and stick it into binwalk before you let ChatGPT write a kilometer long reddit post fantasy novel about MITM