DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

AP810 allows access without password

  • jann
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
22 Jan 2019 21:39 #1 by jann
Starting to setup AP810 Access Point, have connected via cable to switch.
Went to web admin page, entered the usual admin,admin and got usual screens.
Set up a new admin password as advised, at which point the login window appeared, I typed in 'admin' and the new (strong) password, and accessed web admin again fine.

However discovered by accident that simply by typing the web access IP (192.168.1.2) from IE, I now can get straight into the admin pages without being challenged for user/password.
No, did not use anything in IE to 'remember' user/password.
Tried this twice, setting different passwords, same thing.

Did note in passing that unlike e.g. 2860 router, the AP810 screens do not appear to have a logout function, which may/not be relevant.

Latest F/w - 1.2.6 - installed.

Any ideas?

Please Log in or Create an account to join the conversation.

More
23 Jan 2019 18:35 #2 by joners
Replied by joners on topic Re: AP810 allows access without password
Clear your browser cache and test again, could be cached info?

Please Log in or Create an account to join the conversation.

  • jann
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
23 Jan 2019 21:29 #3 by jann
Replied by jann on topic Re: AP810 allows access without password
Thanks, so have tested this again - these are results:

IE11 - for some reason the credentials do get retained for a period, even if 'remember...' is unchecked
Firefox - credentials do not get retained, you have to re-enter

Would imagine the issue is with the AP810 web page rather than IE, in that it is one thing for a page to get cached, another for the credentials to be cached without explicitly requesting the browser to do so (i.e. - with my limited knowledge of browsers - if I request the web address of a device that is meant to be security protected, then it is for the device to refuse to server the protected page due to lack of credentials being re-entered).

But a slight relief anyway, as at least someone would need access to my own browser to get into the AP810 management page(s) - so, some comfort.

Thanks.

Please Log in or Create an account to join the conversation.

Moderators: ChrisSami