A recent security blog Allot-Deepdive exposed that Jio’s base firmware includes a hidden component called "Allot HomeSecure" (cyberiotUserAgent). It acts as a persistent network scanner, brute-forcing SSH/Telnet on your internal LAN devices and exfiltrating credentials to Microsoft Azure C2 servers.
What the original blog missed: To ensure it sees all your network traffic, the firmware disables WiFi AP Isolation. This allows its DPI kernel module to act as an active wiretap on inter-device traffic (e.g., your laptop talking to your NAS). It also uses specific CPU affinity and throttling policies to hide its resource usage, so you don't notice the slowdown.
The Fix (No Root/SSH Required): Jio claimed there was no UI to turn this off, but they just hid the page from the menu.
What the original blog missed: To ensure it sees all your network traffic, the firmware disables WiFi AP Isolation. This allows its DPI kernel module to act as an active wiretap on inter-device traffic (e.g., your laptop talking to your NAS). It also uses specific CPU affinity and throttling policies to hide its resource usage, so you don't notice the slowdown.
The Fix (No Root/SSH Required): Jio claimed there was no UI to turn this off, but they just hid the page from the menu.
- Log into your Jio Router’s Web GUI (Admin).
- Go to the Search bar in the settings.
- Type allot and click on the result.
- This loads a hidden page (allot.html). Flip the toggle to OFF / Disable and click Save.