FCC 47 CFR § 11.35(d) — compliance required by September 29, 2026
Station Compliance

Station Compliance›Equipment›Barix

Equipment note

Barix units ship with no password at all

Not a weak default. Not a well-known default. No password protection in the default configuration. Barix is extremely common as small-market STL, which makes this the highest-priority device class in most stations' program chains.

Verified against manufacturer documentation. Reflects the rule as published August 2026.

Verified. Barix devices in their default configuration provide no password protection at all — access at those levels is open by default. Barix documentation describes security settings that secure access on several levels, with each password shown as set or not set. The shipped state is not set.

Why this matters more than the EAS box

Under 47 CFR § 11.35(d), a Barix unit carrying audio between studio and transmitter is in scope twice over: it is studio-transmitter link equipment, which the rule names explicitly, and it is remotely managed equipment that routes content into programming.

The practical difference from an EAS unit is exposure. EAS encoders tend to be commissioned carefully by someone who understood they were regulated. A Barix pair gets installed to solve an audio transport problem, works perfectly for eight years, and nobody logs into it again — including to set the password it never had.

The documented incident

This is not hypothetical. A broadcaster using Barix equipment to carry audio between studio and a remote transmitter had that equipment reconfigured by an outsider to pull an entirely different stream. Graphic content reached the air.

The attacker then changed the management password, preventing the station from restoring its own settings.

That single incident is the clearest illustration available of what this FCC rule exists to prevent. It required no sophistication — it required a device on the public internet with no password on it.

Also verified

Barix Streaming Client version B3.14 does not require authentication by default. A cross-site scripting issue is documented in the User Agent field under Configuration → Advanced Settings: the field is not sanitized, script inserted there is stored via a POST to /setup.cgi in the S517 parameter, and it renders on uifadvanced.html. This is catalogued as CVE-2015-78000.

The practical reading: an unauthenticated management interface with a stored-script flaw in it is not a device you want reachable from the internet under any circumstances, rule or no rule.

Do this today

Before anything else in your compliance work — this is item two on the priority list, behind only "anything currently port-forwarded":

  1. Confirm every Barix unit has passwords set on all access levels. Not one level. Barix separates them, and the configuration page will tell you which are still not set.
  2. Confirm no Barix unit is reachable from the public internet. Check your router for port-forwarding rules and DMZ assignments pointing at it. Then check from outside — a phone on cellular data, not station Wi-Fi.
  3. Confirm firmware is current. Note the version you are running and the date of the release.
  4. If a Barix unit is currently port-forwarded, treat that as urgent. Replace the forward with a VPN rather than simply deleting it and leaving your engineer no way in at two in the morning.

Then verify the password length yourself

We do not publish maximum password lengths where the manufacturer does not document them, because a guessed number would cause you to record compliance you do not have. Determine it on your own unit in two minutes:

  1. Set a 16-character random password.
  2. Confirm it saves without error.
  3. Log out, and log back in with the full 16 characters.
  4. Then try logging in with only the first 8. If that works, the device is silently truncating your password — a failure that looks exactly like success.

If the unit cannot hold 15 characters, that is an exception: document the limitation, keep the device off the public internet, and record the justification in your own file. The rule also permits equivalent robust authentication where the equipment supports it.

Don't stop at the web password

Most networked broadcast gear offers more than one way in — web, Telnet, SSH, SNMP, a vendor application, sometimes a front panel. These frequently keep separate credential stores. Setting a strong web password on a unit whose Telnet still accepts the factory login changes nothing except your paperwork, which now says you fixed it.

List every management path the device offers, then verify each one separately: log in through it, confirm the new credential works, and confirm the old one does not.

The rest of your rack

Barix is one entry. The Program Chain Compliance Kit covers verified security behavior for DASDEC, Sage ENDEC, Comrex, Tieline, Burk and Inovonics, plus transmitter and audio-over-IP coverage, the credentials that live outside your building, and an eight-step method for anything not listed — with the inventory, port audit and exception templates already written.

See what is in the kit — $149