Experts Find 10 Flaws in Linksys Smart Wi-Fi Routers

Discussion in 'other security issues & news' started by ronjor, Apr 20, 2017.

  1. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,098
    Location:
    Texas
    By Eduard Kovacs on April 20, 2017
     
  2. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
    So a friend of mine is using a higher-end Linksys Wireless Router that is on the list of routers with these vulnerabilities.

    Sophos sums up the three main risks as follows:

    "...The flaws could allow attackers to:

    Cause a Denial of Service (DoS) by sending requests to an unamed API. Admins would be locked out until the attack stopped.

    Use CGI web server scripts to reveal connected devices and computers, dump the WPS Wi-Fi PIN code, and list firmware version and configuration settings.

    Create a hidden “backdoor” account with root privileges and the ability to run commands.

    The third flaw requires an attacker to log in first,..."

    https://nakedsecurity.sophos.com/2017/04/21/multiple-security-holes-discovered-in-linksys-routers/

    He wants to know if he should buy a cheapo, but adequate, router until a patch is issued.

    What would you advise him?

    Does "dump the WPS Wi-Fi PIN code" mean that a someone could hijack onto his bandwith?

    Is it as easy to brute force a router's administrator's PW as it is to brute force any type of PW?
     
  3. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,098
    Location:
    Texas
  4. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
    Thanks ronjor :)

    Will that really cover all the bases?
     
  5. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,098
    Location:
    Texas
    It's probably sufficient at this point. Just because vulnerabilities exist, it doesn't mean you will be attacked immediately if ever.
     
  6. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
    Got it.

    Thanks "=)
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.