Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Downgrade works but it does not make the receiver vulnerable again #1

Closed
phocean opened this issue May 23, 2023 · 7 comments
Closed

Comments

@phocean
Copy link

phocean commented May 23, 2023

As other people report here, while the downgrade operation works, it does not make the device vulnerable again (after an upgrade).

The only solution so far is to purchase again a vulnerable receiver.

@qqmajikpp
Copy link
Owner

qqmajikpp commented May 23, 2023 via email

@qqmajikpp
Copy link
Owner

qqmajikpp commented May 23, 2023 via email

@phocean
Copy link
Author

phocean commented May 30, 2023

No, it really does not work, I have no Logitech software installed and reproduced the issue many times on Windows / Linux.
I found an old, unpatched dongle and it works flawlessly.

I have no idea of what's going on, but apparently something in the firmware cannot be overwritten back with a downgrade. At least not on all dongles, like mine and other people's (I am not the only one to report it so it's probably real).

Not a big issue but I thought it was important to document it, so if someone else gets here they will be aware that it might not work.
I spent an hour on this before finding other people had the same issue and that it was not related to my setup and procedure.

@qqmajikpp
Copy link
Owner

qqmajikpp commented May 30, 2023 via email

@qqmajikpp
Copy link
Owner

qqmajikpp commented May 30, 2023 via email

@qqmajikpp
Copy link
Owner

qqmajikpp commented May 30, 2023 via email

@phocean
Copy link
Author

phocean commented May 31, 2023

The README ? I read it but do not see how it contributes much to the discussion. Yes, I understand you have not tested it on all devices, but I am just reporting that it does not always work, for the sake of documentation as I said.

I am not here for debating / complaining / criticizing / looking for help or anything... Just documenting and sharing so don't take it wrongly, please no drama !

True, I did report what my device is : M325 mouse with stock dongle. This was confirmed to be vulnerable, flashed to patched version and then it's impossible to downgrade. I mean, it downgrades without error, but it's not vulnerable anymore.

I have no idea where the vulnerable dongle that I found in my stuff comes from, but it happens to be a vulnerable version : 024.001.00023.
I paired it with the mouse and it just works.

So, definitely no issue and not needing help, just reporting.

That's it for me, I won't comment here anymore. Thank you and have fun.

@phocean phocean closed this as completed May 31, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants