215
people found this helpful, as of 2023
ranked #144,974 most helpful
out of 571,544,897 reviews
★★★★★
Best performing and most reliable, but big potential for security issues
~Update 12/2018~
My original review is below for reference, but as one of the recent comments on the review pointed out, Extollo has updated their website and added better documentation on setting up the devices. The documentation also goes into accessing and using the web management GUI. It only touches on the basics of the GUI (viewing/managing the Homeplug stuff, changing the default user account passwords, and updating the software), but for most people that should be all they need to worry about. They also fleshed out the instructions for using the sync button to create a network and add more devices to an existing network, which is another plus. I could never get that part to work following their previous documentation.
Another welcome update is they actually released a firmware update for the adapters. The update bumps the firmware version from 3.2.0 to 3.2.4. From the limited information I could glean from other manufacturers with devices using the same chipset, this is the newest firmware available for the Broadcom BCM60500 chipset. After updating the firmware, I've noticed better overall performance, with slightly lower latency, and better connection speeds (both reported via the utility and in real-world network transfers).
While the firmware was updated, however, the embedded Linux software on the device is exactly the same as the old version. Fortunately, I re-ran vulnerability scanner and it still only came back with the three previously reported items, so as long as your use these devices behind your home router, they should continue to be perfectly safe to use (as long as you keep your router updated too).
After considering how well these devices have been holding up over the ~2 years I've had them, I decided to change my rating to a 5 star, up from a 3. These are still the best performing Homeplug AV2 adapters available; they improved the documentation of their devices by adding the information about the web interface; and they updated the firmware as far as it could go, 3 years after they first shipped. Not updating the Linux firmware is disappointing, but mitigating the security risk there is easy enough. More importantly, supporting a consumer product this long after release is very uncommon. I don't know if any more software updates will be released, but at least we have the best we can get.
~Original Review~
These are by far the best performing and most reliable HomePlug adapters I have ever used. I haven't experienced a single connection drop while using them, and they don't cause any significant speed degradation to my PC's connection to the Internet. They also perform around ~12% faster with LAN traffic than the Netgear PLP1200 adapters I was previously using. Another nice feature is these don't block the top outlet like every other HomePlug devices do, you can also still use the second outlet too. The pair came with CAT5 cables, so you will want to upgrade to CAT5e or CAT6 cable to get full use out of the Gigabit Ethernet port too.
I had to take a star away because of some security concerns I have with these adapters. I took another star away because the documentation available is lacking in some important areas.
Unlike all other HomePlug devices, these devices run an embedded Linux distro. This is a beneficial feature because it allowed the vendor to load more memory onto the devices, which is part of the reason they perform so well. The downside, though, is they are now accessible over Layer 3 (so they get assigned an IP address and you can connect and login to them).
This leads to some security implications:
1) They running a web server over port 80 (unencrypted)
2) They have 3 built-in accounts that have preset, easily guessed passwords (admin, support, user)
3) They run telnet on port 23 (unencrypted)
The web interface on these devices is where configuration is meant to be done (unlike other HomePlug devices where there is a separate application to configure them). You can also track some performance information from the web interface, and these devices also run an nVoy client, which is a hybrid home network protocol standard (so you can actually see other nVoy devices in your home or neighborhood). The vendor's documentation on their website, however, doesn't mention the web interface at ALL.
From the web interface, you can easily change the passwords to the 3 built-in user accounts (which is good), but because these devices can be accessed over http on 80 or telnet on port 23, the connection is not encrypted so the login information could be intercepted if your network is compromised. You can also disable the nVoy client to reduce the device's visibility (also good). There are other features that sound like they could be set up to further harden the devices, but without documentation I don't know how to make them work. It looks like the firmware they are running was designed for cheap embedded routers, so there are options that I can't believe will do anything since the needed hardware is missing.
Because they are running embedded Linux with some other open-source software components, I decided to run a vulnerability scan against one of these using Nexpose Community edition. I provided the scanner with the login credentials for the Admin account so it could probe the software internally as well. After a long (4 hour) scan, I was happy to see that Nexpose only reported on 3 issues:
Unencrypted Telnet Service Available (severe)
TCP timestamp response (moderate)
ICMP timestamp response (moderate)
The biggest concern is the Unencrypted Telnet Service. The TCP and ICMP timestamp responses can't be disabled, and may actually be used by the software to communicate with each other (which is why they are on). The concern with the timestamps is they could be used by an attacker to determine the device uptime. Luckily, all of these issues can be mitigated by running them behind a router with a built-in firewall (which 99% of all consumer routers have). As long as there is no exploit for the router and you properly encrypt the HomePlug traffic, these devices will be safe to use on your home network. This also means, as of 02/2017, there are no known vulnerabilities for the embedded software running on the devices too.
Therefore, these are safe to use as long as they are run on your local network (behind your home router). If you are planning on using them to move your router to a different location (that is, you plug one directly into your modem, and then use the other to relocate your router to some other place in your house), then you will have a big security concern because the web interface and telnet will be detectable and accessible from the Internet.
My recommendations on the safest way to use these are:
1. Run these devices behind a router with a built-in firewall (most important, do NOT connect them directly to the Internet)
2. Change the password to the three built in user accounts (admin, support, user)
3. Manually assign these devices static IP addresses on your LAN (to keep track of them better)
4. If you are able to, block these devices on your router from accessing the Internet directly (they will still pass traffic to your router and allow other devices to get out to the Internet. This is just keeping them from getting to the Internet on their own)
5. Change the Homeplug network name (either using the "Secure" button on the device or from the web interface) to encrypt the HomePlug traffic
6. Disable the nVoy client
So overall, if you understand everything I wrote above and know how to do the steps I laid out, then I recommend these as an easy solution to create a fast and reliable wired network connection. Do NOT connect them directly to the Internet. If you don't understand what I wrote above, then I recommend you go with a different solution. Any of the other HomePlug AV2-2000 class devices are running the same chipset as these, so should perform similarly without the potential security concerns.
It remains to be seen if the vendor will provide software updates (either to fix bugs or address any security vulnerabilities). I'm very happy with how these work though and will probably purchase additional ones.
February 2017 · Electronics · verified purchase