Station Compliance›Equipment›Barix
Equipment note
Not a weak default. Not a well-known default. No password protection in the default configuration. Barix is extremely common as small-market STL, which makes this the highest-priority device class in most stations' program chains.
Verified against manufacturer documentation. Reflects the rule as published August 2026.
Verified. Barix devices in their default configuration provide no password protection at all — access at those levels is open by default. Barix documentation describes security settings that secure access on several levels, with each password shown as set or not set. The shipped state is not set.
Under 47 CFR § 11.35(d), a Barix unit carrying audio between studio and transmitter is in scope twice over: it is studio-transmitter link equipment, which the rule names explicitly, and it is remotely managed equipment that routes content into programming.
The practical difference from an EAS unit is exposure. EAS encoders tend to be commissioned carefully by someone who understood they were regulated. A Barix pair gets installed to solve an audio transport problem, works perfectly for eight years, and nobody logs into it again — including to set the password it never had.
This is not hypothetical. A broadcaster using Barix equipment to carry audio between studio and a remote transmitter had that equipment reconfigured by an outsider to pull an entirely different stream. Graphic content reached the air.
The attacker then changed the management password, preventing the station from restoring its own settings.
That single incident is the clearest illustration available of what this FCC rule exists to prevent. It required no sophistication — it required a device on the public internet with no password on it.
Barix Streaming Client version B3.14 does not require authentication by default. A cross-site scripting issue is documented in the User Agent field under Configuration → Advanced Settings: the field is not sanitized, script inserted there is stored via a POST to /setup.cgi in the S517 parameter, and it renders on uifadvanced.html. This is catalogued as CVE-2015-78000.
The practical reading: an unauthenticated management interface with a stored-script flaw in it is not a device you want reachable from the internet under any circumstances, rule or no rule.
Before anything else in your compliance work — this is item two on the priority list, behind only "anything currently port-forwarded":
We do not publish maximum password lengths where the manufacturer does not document them, because a guessed number would cause you to record compliance you do not have. Determine it on your own unit in two minutes:
If the unit cannot hold 15 characters, that is an exception: document the limitation, keep the device off the public internet, and record the justification in your own file. The rule also permits equivalent robust authentication where the equipment supports it.
Most networked broadcast gear offers more than one way in — web, Telnet, SSH, SNMP, a vendor application, sometimes a front panel. These frequently keep separate credential stores. Setting a strong web password on a unit whose Telnet still accepts the factory login changes nothing except your paperwork, which now says you fixed it.
List every management path the device offers, then verify each one separately: log in through it, confirm the new credential works, and confirm the old one does not.
Barix is one entry. The Program Chain Compliance Kit covers verified security behavior for DASDEC, Sage ENDEC, Comrex, Tieline, Burk and Inovonics, plus transmitter and audio-over-IP coverage, the credentials that live outside your building, and an eight-step method for anything not listed — with the inventory, port audit and exception templates already written.