Multiple critical vulnerabilities discovered in ASUS Routers that allow an attacker can able to gain complete control of the router access and this flaw existed in all the AsusWRT Routers.
There are 4 Vulnerabilities has been reported and all together will provide complete router access to attacker once router administrator login with his admin credentials then this flaw allows for retrieving the login/password using Administrator token.
According to seclists full disclosure, all the vulnerabilities are noticed to vendors and fixes has been realized.
Also Read Self-Destructive KillDisk Malware Overwrites then Deletes files and Force a Reboot
This vulnerability allows an attacker can guess the administrator Login token in Router Which can be used to gain the admin user credentials when admin logged in the session.
stdlib rand function helps to generate a session token for an authenticated user and the Specific set of code initializes the random number generator each time a token is generated with router Login time.
Once attacker gain the session token using the Previous Vulnerability(CVE-2017-15653) attacker will perform the IP Verification mechanism and he will use special user-agent by sending the request.
Later Following Proof of Concept will be used for download current router configuration even if issued from a different than the logged user IP address
curl "http://ROUTERADDRESS/s.CFG" -H "Cookie: asus_token=TOKEN" -H 'User-Agent:
asusrouter-asusrouter-asusrouter-asusrouter'
Asus routers stored all the passwords in the Plaintext in NVRAM memory which allow to downloading the backup and decode the password which leads to anyone can extract and see the admin password by Executing NVRAM (Show NVRAM).
Based on the all 3 major flaw Attack finally can able to retrieve the active session and exploit the router and gain the admin level access and the possible attacker can control the complete network that connected with compromised Router.
Along with above vulnerability Heap buffer overflow in multiple HTTP headers allows for an unauthenticated remote code execution for the routers not upgradable from 3.0.0.4.376.
This vulnerability also have been fixed and assigned CVE(CVE-2017-15655)
All these Vulnerabilities are notified to the specific vendor and they release a fixed version 3.0.0.4.382.18495.
But vendor REFUSED to fix the vulnerability as the routers using the vulnerable firmware are already EOL for Head Buffer Overflow.
A groundbreaking technique for Kerberos relaying over HTTP, leveraging multicast poisoning, has been recently detailed…
Since mid-2024, cybersecurity researchers have been monitoring a sophisticated Android malware campaign dubbed "Tria Stealer,"…
Proton, the globally recognized provider of privacy-focused services such as Proton VPN and Proton Pass,…
The cybersecurity landscape faces increasing challenges as Arcus Media ransomware emerges as a highly sophisticated…
Proofpoint researchers have identified a marked increase in phishing campaigns and malicious domain registrations designed…
A recent investigation by Unit 42 of Palo Alto Networks has uncovered a sophisticated, state-sponsored…