Tuesday, November 26, 2024
HomeSecurity NewsAll Versions of ASUS Routers Affected by Multiple Vulnerabilities that Allows to...

All Versions of ASUS Routers Affected by Multiple Vulnerabilities that Allows to Gain Complete Router Access

Published on

Multiple critical vulnerabilities discovered in ASUS Routers that allow an attacker can able to gain complete control of the router access and this flaw existed in all the AsusWRT Routers.

There are 4 Vulnerabilities has been reported and all together will provide complete router access to attacker once router administrator login with his admin credentials then this flaw allows for retrieving the login/password using Administrator token.

According to seclists full disclosure, all the vulnerabilities are noticed to vendors and fixes has been realized.

- Advertisement - SIEM as a Service

Also Read Self-Destructive KillDisk Malware Overwrites then Deletes files and Force a Reboot

Highly Predictable Session Tokens (CVE-2017-15654)

This vulnerability allows an attacker can guess the administrator Login token in Router Which can be used to gain the admin user credentials when admin logged in the session.

stdlib rand function helps to generate a session token for an authenticated user and the Specific set of code initializes the random number generator each time a token is generated with router Login time.

Not Sufficient logged user IP validation(CVE-2017-15653)

Once attacker gain the session token using the Previous Vulnerability(CVE-2017-15653) attacker will perform the IP Verification mechanism and he will use special user-agent by sending the request.

Later Following Proof of Concept will be used for download current router configuration even if issued from a different than the logged user IP address

 curl "http://ROUTERADDRESS/s.CFG" -H "Cookie: asus_token=TOKEN" -H 'User-Agent:
asusrouter-asusrouter-asusrouter-asusrouter'

Password Stored in Plain Text (CVE-2017-15656)

Asus routers stored all the passwords in the Plaintext in NVRAM memory which allow to downloading the backup and decode the password which leads to anyone can extract and see the admin password by Executing NVRAM (Show NVRAM).

Logged-in Information disclosure

Based on the all 3 major flaw Attack finally can able to retrieve the active session and exploit the router and gain the admin level access and the possible attacker can control the complete network that connected with compromised Router.

Heap buffer overflow – ASUS Routers

Along with above vulnerability Heap buffer overflow in multiple HTTP headers allows for an unauthenticated remote code execution for the routers not upgradable from 3.0.0.4.376.

This vulnerability also have been fixed and assigned  CVE(CVE-2017-15655)

All these Vulnerabilities are notified to the specific vendor and they release a fixed version 3.0.0.4.382.18495.

But vendor REFUSED to fix the vulnerability as the routers using the vulnerable firmware are already EOL for Head Buffer Overflow.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Blue Yonder Ransomware Attack Impacts Starbucks & Multiple Supermarkets

A ransomware attack on Blue Yonder, a leading supply chain management software provider, has...

Dell Wyse Management Suite Vulnerabilities Let Attackers Exploit Affected Systems Remotely

Dell Technologies has released a security update for its Wyse Management Suite (WMS) to...

CISA Details Red Team Assessment Including TTPs & Network Defense

The Cybersecurity and Infrastructure Security Agency (CISA) recently detailed findings from a Red Team...

IBM Workload Scheduler Vulnerability Stores User Credentials in Plain Text

IBM has issued a security bulletin warning customers about a vulnerability in its Workload...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Nearest Neighbor Attacks: Russian APT Hack The Target By Exploiting Nearby Wi-Fi Networks

Recent research has revealed that a Russian advanced persistent threat (APT) group, tracked as...

Critical PDF.js & React-PDF Vulnerabilities Threaten Millions Of PDF Users

A new critical vulnerability has been discovered in PDF.js, which could allow a threat...

LayerX Security Raises $26M for its Browser Security Platform, Enabling Employees to Work Securely From Any Browser, Anywhere

LayerX, pioneer of the LayerX Browser Security platform, today announced $24 million in Series...