News

White Hat Hacker Exposes Security Exploits In Linksys’ Wi-Fi Routers


Phil Purviance, an information security specialist for AppSec Consulting exposed a vulnerability in Linksys EA2700 Network manager. The network manager has a cross-site request forgery exploit and also doesn’t require the current password to be used even when the passcode has been changed.

He also found a security bug in WRT54GL, but added that some of the exploits can be taken advantage of only if the attacker can correctly guess the default gateway of the router. But since most users don’t really change that, the attackers will use the common IP address required to gain access with the Linksys router. There is a fix for that, and that’s upgrading WRT54GL with the newer Linksys Smart Wi-Fi firmware.

According to Phil, once both of these exploits are taken advantage of together, any attackers can gain full access and take over the router as soon as the end-user is lured-in to a booby-trapped website. The website will embed a malicious javascript in the end user’s browser which will reset the router’s password and turns on its remote management and hence gaining administrator privileges over the router.

Purviance told Ars Technica,”If you have this router on your network and you browse a malicious website, five seconds later your router now has a new password and is available from the Internet. So an attacker can just log into it as if he was on your network.”

Belkin recently acquired the Linksys brand from Cisco, but it needs to do the patch on the existing routers. The company assured that the findings by Purviance will be used to fix the issue on Linksys’ Smart Wi-Fi firmware.

The company made a statement:
Network security is top of mind in everything we do. We have a layered approach via our hardware and software that provides immediate protection for our customers out of the box and enables us to react to new vulnerabilities quickly.

Source: Ars Technica

Roshan Ashraf Shaikh

Disqus Comments Loading...

Recent Posts

S.T.A.L.K.E.R. 2: Heart of Chornobyl Gets A New Trailer

While I'm not familiar with the Bilibili streaming platform, it was the source of a…

39 mins ago

Jensen Huang to Kick Off Computex 2024 With NVIDIA Keynote

As Computex 2024 approaches, the tech industry buzzes with anticipation for a series of high-profile…

1 day ago

MSI Prioritizes NVIDIA Over AMD as RX 7000 GPU Supplies Vanish

MSI, a key player in the graphics card market, appears to be shifting its focus…

1 day ago

TeamGroup Clinches Four Red Dot Awards for Innovative Design

TeamGroup has once again proven its prowess in the field of memory product innovation by…

1 day ago

eFootball Hits Major Milestone with 750 Million Downloads

Konami's eFootball has reached a staggering 750 million downloads worldwide. This milestone comes as the…

1 day ago

Manor Lords Is Out Now On Steam, Epic and Gamespass!

Just a few hours after its release on Steam alone Manor Lords has already managed…

2 days ago