Security researchers recently found a bug on Comcast Xfinity’s official account activation website that allows attackers to easily obtain customers’ WiFi names and passwords.
ZDNet reported on the issue after getting a tip from security researchers Karan Saini and Ryan Stevenson. The subject of the bug was Xfinity’s official website where customers activate online services for their accounts.
According to the report and based on their own testing, the bug allows unauthorized people to obtain WiFi names and passwords of customers who are using Xfinity-provided routers. To illicitly collect these data, an attacker will only need to enter the target’s residential address.
These issues were confirmed by the publication after two Xfinity customers agreed to participate in the test and provided their home addresses.
The experiment revealed that the bugged website provided the correct WiFi name and password of the customer who uses an Xfinity router. Even worse, the website gave these data in plaintext or in its unencrypted, unscrambled form. So, ultimately, an attacker needs one information to intrude a personal WiFi connection.
The security issue does not end there. It was also found that the glitched website gives information of an Xfinity customer even when their WiFi connection is active and even after they have changed their WiFi name and password.
Though the compromised website requires a customer’s complete address, ZDNet commented that an attacker can gather that information by simply guessing a house number or, more easily, by snatching a utility bill thrown in the garbage.
By simply providing a customer’s address, an attacker can tamper the WiFi name and password of Xfinity routers — even custom ones — and later avoid the actual user to access his or her own WiFi connection.
As of this writing, the said website is still up and running and TechCrunch noted that the issue appears to still be in place. And since the bug appears to be useless when aimed at customers with a non-Xfinity router, buying one seems to be the only possible solution for now.


Alphabet’s Massive AI Spending Surge Signals Confidence in Google’s Growth Engine
Instagram Outage Disrupts Thousands of U.S. Users
Amazon Stock Rebounds After Earnings as $200B Capex Plan Sparks AI Spending Debate
Sony Q3 Profit Jumps on Gaming and Image Sensors, Full-Year Outlook Raised
Palantir Stock Jumps After Strong Q4 Earnings Beat and Upbeat 2026 Revenue Forecast
Nvidia CEO Jensen Huang Says AI Investment Boom Is Just Beginning as NVDA Shares Surge
Oracle Plans $45–$50 Billion Funding Push in 2026 to Expand Cloud and AI Infrastructure
SoftBank Shares Slide After Arm Earnings Miss Fuels Tech Stock Sell-Off
SoftBank and Intel Partner to Develop Next-Generation Memory Chips for AI Data Centers
AMD Shares Slide Despite Earnings Beat as Cautious Revenue Outlook Weighs on Stock
Anthropic Eyes $350 Billion Valuation as AI Funding and Share Sale Accelerate
Baidu Approves $5 Billion Share Buyback and Plans First-Ever Dividend in 2026
OpenAI Expands Enterprise AI Strategy With Major Hiring Push Ahead of New Business Offering
Nvidia Nears $20 Billion OpenAI Investment as AI Funding Race Intensifies
Tencent Shares Slide After WeChat Restricts YuanBao AI Promotional Links
TSMC Eyes 3nm Chip Production in Japan with $17 Billion Kumamoto Investment
Global PC Makers Eye Chinese Memory Chip Suppliers Amid Ongoing Supply Crunch 



