Researchers discovered multiple vulnerabilities with some NETGEAR wireless routers that allow an attacker to access sensitive information. The vulnerability exists in the KCodes’ NetUSB kernel module.
Only specific models of NETGEAR wireless routers use the kernel module from KCodes; the module shares USB devices over TCP, which allows clients to connect with various drivers and software.
According to Talos researcher, Dave McDaniel, “An attacker could send specific packets on the local network to exploit vulnerabilities in NetUSB, forcing the routers to disclose sensitive information and even giving the attacker the ability to remotely execute code.”
The arbitrary memory read vulnerability exists in the KCodes NetUSB.ko kernel module; an unauthenticated attacker can trigger this vulnerability form a local network by sending a crafted packet with an invalid memory read that could result in denial of service or remote information disclosure.
An exploitable information disclosure vulnerability that resides with KCodes NetUSB.ko kernel module let an unauthenticated, remote attacker send a crafted packet with containing an opcode that will trigger the kernel module to return several addresses.
Cisco reached out to KCodes and NETGEAR regarding this vulnerability, and the update is scheduled to release.
Also, Cisco decided to release the details of our vulnerability after surpassing its 90-day deadline.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.
Related Read:
More than 25,000 Linksys Smart Wi-Fi Routers Leaking Sensitive Information to the Public Internet
Verizon Fios Router Vulnerabilities Allows Attackers to Gain Complete Control Over the Network
Phishing attackers used Google Docs to deliver malicious links, bypassing security measures and redirecting victims…
The Python-based NodeStealer, a sophisticated info-stealer, has evolved to target new information and employ advanced…
A significant XSS vulnerability was recently uncovered in Microsoft’s Bing.com, potentially allowing attackers to execute…
Meta has announced the removal of over 2 million accounts connected to malicious activities, including…
Critical security vulnerability has been identified in Veritas Enterprise Vault, a widely-used archiving and content…
A critical security vulnerability has been disclosed in the popular file archiving tool 7-Zip, allowing…