Security – Is Selling Old Cisco Routers a Security Issue?

ciscorouterSecurity

I'm a system admin but I'm not Cisco certified and I'm not a network engineer. Basically I only use switches/routers/modems with a GUI.

I've inherited a pile of old Cisco routers that are not in use and am looking at selling them.

I don't have a console cable handy and I've just spend 30 minutes getting nowhere attempting to reset an 878 back to factory defaults (and there's about 5 more of these).

Is there a security problem selling/recycling these without factory defaulting them? They're all password protected so I assume no-one can recover data/passwords from them as they'd need to factory default them anyway?

TIA

Best Answer

If you have console access to a Cisco Router you can use Cisco Password Recovery techniques to get in, then dump the cleartext config file via TFTP - you then have access to cleartext passwords, or passwords that are trivial to decrypt.

So you do need to factory reset. If you haven't got the login details for the routers (in which case you can probably get in via SSH over a network connection), then you will need to use the above techniques to get in, then issue the write erase command to drop the existing configs.