San FranciscoPopanet routes through 2 million devices, Google found.
Clean home IP addresses now sell to criminals hiding fraud and DDoS traffic.
SuperBox ships with an unauthenticated open root port, letting anyone install malware over the network.
Security firm Plume urges owners to disconnect and discard the boxes immediately.
How each outlet framed it
- Ars Technica leans critical
- maps vulnerability chain: open ADB port plus default proxy apps enable silent APK installation, bypassing Android security
Sources: Ars Technica