Home > Security News > 'Serious' security holes in Linksys router
Security News:
EMAIL THIS

'Serious' security holes in Linksys router

By Bill Brenner, News Writer
14 Sep 2005 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Attackers could exploit a variety of security holes in the Linksys WRT54G wireless router to tamper with passwords and firewalls, install firmware or cause a denial of service, iDefense warned in a series of advisories Wednesday.

"Some of these vulnerabilities are very serious," the Bethesda, Md.-based SANS Internet Storm Center warned on its Web site. "Users of these products are highly recommended to patch their devices."

Linksys is a division of San Jose, Calif.-based networking giant Cisco Systems, whose routers and switches make up a significant part of the Internet's infrastructure. Its WRT54G model is a combination wireless access point, switch and router. According to iDefense, which is part of Mountain View, Calif.-based VeriSign Inc.:

The first problem is a design error unauthenticated users could exploit to modify the router configuration.

"The vulnerability specifically exists in the 'ezconfig.asp' handler of the httpd running on the internal interfaces, including, by default the wireless interface," iDefense said. "Successful exploitation… would allow an unauthenticated user… to modify the configuration of the affected router, including the password. This could allow firewall rules to be changed, installation of a new firmware with other features, or denial of service."

More recent news on Cisco and iDefense:

Cisco IOS flaw prompts Symantec to raise threat level

 

VeriSign acquisition: Will iDefense keep looking underground for flaws?

The second problem is a buffer overflow vulnerability in the "apply.cgi" handler of the httpd running on the internal interfaces, including, by default, the wireless interface.

"Successful exploitation… would allow an unauthenticated user to execute arbitrary commands on the affected router with root privileges," iDefense said. "This could allow any operation to be performed on the router, including changing passwords and firewall configuration, installation of new firmware with other features, or denial of service."

The third problem is a design error in the router's "restore.cgi'" component. The security hole specifically exists in the "POST" method of the "restore.cgi" handler. The httpd running on the internal interfaces, including by default the wireless interface, does not check if authentication has failed until after data supplied by an external user has been processed, iDefense said.

"Successful exploitation… would allow an unauthenticated user… to modify the configuration of the affected router, including the password," iDefense said. "This could allow firewall rules to be changed, installation of a new firmware with other features, or denial of service."

The fourth problem is a design error in the router's "upgrade.cgi" component when the "POST" method is used. The httpd running on the internal interfaces, including, by default, the wireless interface, does not check if authentication has failed until after data supplied by an external user has been processed. The upgrade.cgi handler allows a user to upload new firmware, which contains the operating system and applications, into the non-volatile memory of the router, the advisory said.

"Successful exploitation… would allow an unauthenticated user… to completely compromise the affected router, by installation of an arbitrary firmware," iDefense said. "As the source code and tools for compiling the firmware are available from the vendor, an attacker could simply rebuild the firmware and add the extra functionality."

The fifth problem is an input validation error within the router's Web management httpd component. The flaw is in several of the "POST" method handlers of the httpd running on the router's internal interfaces, including, by default, the wireless interface.

"In addition to not checking if authentication has failed until after data supplied by an external user has been processed, there are several places where the Content-Length is assumed to be valid," iDefense said. "In some of those cases, data is read in without error checking while decrementing the length value. If the Content Length is set to a negative number, these checks will take an extremely long time, during which the httpd will become unresponsive."

The advisories specify which versions of the product are affected by the various flaws and outlines the workarounds and fixes.

Tags: Vulnerability Risk AssessmentConfiguration Management PlanningSecurity Patch ManagementWireless LAN Design and SetupVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Vulnerability Risk Assessment
Are Web application penetration tests still important?
McAfee to acquire Solidcore Systems for whitelisting
The Pipe Dream of No More Free Bugs
Vulnerability test methods for application security assessments
Free HP SWFScan tool detects Adobe Flash flaws
PCI QSA assurance program penalizes assessors
Information security book excerpts and reviews
New York drafts language demanding secure code
Security experts identify 25 dangerous coding errors
Microsoft Windows XML flaw exploits test desktop antimalware
Vulnerability Risk Assessment Research

Configuration Management Planning
EMC adds configuration management with Configuresoft acquisition
McAfee to acquire Solidcore Systems for whitelisting
Product Review: Shavlik's NetChk Compliance
Security services: Fiberlink's MaaS360 Mobility Platform
CISSP Essentials training: Domain 10, Operations Security
5 Steps for Developing Strong Change Management Program Best Practices
Misconfiguration issues could have contributed to Hannaford breach
Misconfigured networks create huge security risks
Private sector should learn from government insecurity
Compliance drives security configuration management
Configuration Management Planning Research

Security Patch Management
Adobe fixes critical Shockwave Flash Player flaw
Mozilla patches 11 Firefox security flaws, JavaScript errors
Microsoft patches WebDAV security vulnerability in bevy of updates
Adobe issues first quarterly patch release fixing 13 flaws
Microsoft plans 10 security updates, fixing IE, Word, Excel vulnerabilities
Adobe shifts to Microsoft patching process, incident response plan
Software delivery could fix software patching issues
Microsoft updates Office to address serious PowerPoint vulnerabilities
Microsoft to patch critical PowerPoint zero-day flaw
Firefox update addresses several security flaws

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
gray hat  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts