home.social

#routersecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #routersecurity, aggregated by home.social.

fetched live
  1. CVE-2026-16096: HIGH severity stack buffer overflow in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124 (/proc/webmon_recent_domains). Remote exploit possible, no official patch. Migrate to FreshTomato. radar.offseq.com/threat/a-vuln #OffSeq #Vulnerability #RouterSecurity #CVE #IoT

  2. 😐 Аналітична доповідь: позов штату Техас проти TP-Link Systems Inc.

    1. Суть позову

    Генеральний прокурор штату Техас ініціював судове провадження проти TP-Link Systems Inc. за кількома напрямами:

    Оманливе маркування походження: продукція просувалася як «Made in Vietnam», тоді як критичні елементи виробництва та supply chain прив’язані до Китаю.

    Недостовірні заяви про безпеку: пристрої позиціонувалися як secure-by-design, попри наявність численних firmware-вразливостей.

    Кіберризики державного рівня: за твердженням позову, уразливості могли експлуатуватися структурами, пов’язаними з китайськими державними кіберопераціями.

    ---

    2. Юридична рамка

    Позов, імовірно, базується на:

    Законодавстві про захист прав споживачів (Deceptive Trade Practices)

    Data privacy regulation (state-level)

    Потенційно — норми, що стосуються національної безпеки (якщо доведено зв’язок із державними акторами)

    ---

    3. Ключові вимоги прокуратури

    Суду пропонується:

    🚫 Заборонити заяви про «виробництво у В’єтнамі» без прозорої деталізації

    🌐 Примусити до розкриття зв’язків із китайськими структурами

    🔐 Обмежити або призупинити збір даних без явної згоди користувачів

    🛠 Зобов’язати усунути бекдори та критичні вразливості

    ⚖️ Провести jury trial (суд присяжних)

    ---

    4. Технічний аспект (кібербезпека)

    Проблематика не нова для сегмента SOHO-обладнання:

    Часті кейси hardcoded credentials

    Вразливості в web-interface та remote management API

    Відсутність своєчасних security patches

    Ризик використання пристроїв у botnet-інфраструктурі (аналогії з Mirai-подібними сценаріями)

    Якщо твердження про бекдори підтвердяться, це переводить кейс із комерційної площини в геополітичну.

    ---

    5. Геополітичний контекст

    Цей позов вписується у ширший тренд:

    ескалація технологічного протистояння США — Китай

    підвищена увага до supply chain transparency

    кейси проти Huawei та ZTE як прецеденти

    TP-Link, як масовий постачальник мережевого обладнання, стає критичною точкою ризику через масштаб інсталяцій.

    ---

    6. Потенційні наслідки

    Для TP-Link:

    штрафи та примусові зміни маркетингової політики

    аудит безпеки продуктів

    репутаційні втрати на глобальному ринку

    Для ринку:

    посилення вимог до origin disclosure

    тренд на security certification для consumer-grade пристроїв

    перерозподіл частки ринку на користь альтернативних брендів

    Для користувачів:

    зростання обізнаності щодо ризиків мережевого обладнання

    попит на open-source firmware (OpenWRT-клас рішень)

    ---

    7. Висновок

    Позов проти TP-Link Systems Inc. — це не лише про маркування або маркетинг. Це комбінований кейс на перетині кібербезпеки, споживчого права та геополітики, який може сформувати нові стандарти прозорості для всього сегмента мережевого обладнання.

    ---

    #хештеги

    #TPLink #Texas #кибербезпека #CyberSecurity #China #USA #DataPrivacy #Backdoor #IoT #RouterSecurity #Firmware #InfoSec #SupplyChain #TechWar #Huawei #ZTE #мережі #інтернетбезпека #botnet #вразливості #геополітика #санкції #аналіз #security #privacy

  3. 🚩 CRITICAL: CVE-2026-4252 impacts Tenda AC8 (16.03.50.11). IP-based auth in IPv6 Handler lets remote attackers bypass login. Exploit is public. Disable remote mgmt, restrict access, monitor traffic. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE #RouterSecurity #Infosec

  4. 🚩 CVE-2026-3768 (HIGH, CVSS 8.7): Stack buffer overflow in Tenda F453 v1.0.0.3 — remote, unauthenticated exploit possible. Public exploit code released. Patch ASAP or restrict remote access! radar.offseq.com/threat/cve-20 #OffSeq #CVE20263768 #RouterSecurity #Infosec

  5. A critical RCE vulnerability in legacy D-Link DSL routers allows unauthenticated attackers to execute arbitrary commands with root privileges.

    With the devices now End-of-Life and no patch expected, immediate replacement is the only recommended mitigation.

    Details:
    technadu.com/critical-rce-vuln

    #RCE #IoTSecurity #RouterSecurity #Infosec #VulnerabilityManagement

  6. LB-LINK routers (BL-AC1900 & more, ≤20250702) face CRITICAL risk: CVE-2025-7574 allows remote, unauthenticated reboot/restore via /cgi-bin/lighttpd.cgi. Public exploit, no patch yet. Restrict access & monitor! radar.offseq.com/threat/cve-20 #OffSeq #RouterSecurity #CVE20257574

  7. 🔎 HIGH severity (CVSS 8.7) stack buffer overflow in TOTOLINK EX1200T (4.1.2cu.5232_B20210713) via /cgi-bin/cstecgi.cgi. Public exploit code—remote takeover possible. Restrict access & patch ASAP. CVE-2025-6302 radar.offseq.com/threat/cve-20 #OffSeq #Vuln #RouterSecurity #InfoSec

  8. 🚨 FBI Warning: TheMoon malware is back — targeting end-of-life routers to install proxies & hide criminal activity.

    🛑 No patches = high risk.

    𝗥𝗘𝗟𝗜𝗔𝗡𝗢𝗜𝗗 𝗘𝗘 𝘃𝗲𝗿𝘀𝗶𝗼𝗻 𝟲 𝘄𝗶𝗹𝗹 𝗿𝗲𝗮𝗰𝗵 𝗘𝗻𝗱 𝗼𝗳 𝗟𝗶𝗳𝗲 𝘁𝗵𝗶𝘀 𝗝𝘂𝗻𝗲. Upgrade now to v8+ for:

    ⚡ Fast proxy engine
    🌐 HTTP/2 support
    🔄 Hot restarts
    🛡️ Stronger security

    👉 Stay protected:
    relianoid.com/blog/malware-tar

  9. The FBI has issued an alert about cybercriminals hijacking outdated routers to power massive proxy-for-hire networks—masking malware, fraud, and credential theft right under your nose.

    Watch the full Cyberside Chats episode to hear @sherridavidoff and @MDurrin 's insights on:

    🔹 The FBI’s May 2025 alert
    🔹 TheMoon malware and the Faceless proxy service
    🔹 What these botnets mean for your enterprise
    🔹 What you need to do now to stay protected

    🎥 Watch the video: youtu.be/x_40BlvWsHk
    🎧 Listen to the podcast: chatcyberside.com/e/outdated-r

    #Cybersecurity #RouterSecurity #ThreatIntel #Malware #CISO #CybersideChats #ProxyAbuse #TheMoonMalware #Botnets #NetworkSecurity #CISO #Cyberaware #Tech #Infosec #IT #CIO #SMB #Cyber

  10. Cuttlefish Zero-Click Malware: Stealthy Theft of Cloud Data through Routers

    Date: May 1, 2023
    CVE: Not specified
    Vulnerability Type: Malware
    CWE: [[CWE-200]], [[CWE-287]], [[CWE-311]]
    Sources: Dark Reading

    Issue Summary

    Cuttlefish is a newly identified malware that targets enterprise and SOHO routers (Small Office/ Home Office) to steal authentication details without user interaction. Designed by Black Lotus Labs, this zero-click malware infiltrates network equipment to capture data, leveraging DNS and HTTP hijacking to interact with private IP addresses and exfiltrate data via proxy or VPN tunnels. Cuttlefish has been active since at least last July, with its latest campaign running from October through April 2024.

    Technical Key findings

    Cuttlefish uses a sophisticated method that involves sniffing packets and hijacking DNS and HTTP requests. It deploys via a bash script, gathering data and executing a malicious binary. It monitors network traffic, activating based on predefined rules to target private IP addresses or steal credentials. Researchers found links — specifically, code similarities and embedded build paths — to HiatusRat, thus they believe Cuttlefish also is aligned with the interests of China-based threat actors. To exfiltrate data, the threat actor first creates either a proxy or VPN tunnel back through a compromised router, then uses stolen credentials to access targeted resources," according to the post. "By sending the request through the router, we suspect the actor can evade anomalous sign-in based analytics by using the stolen authentication credentials."

    Vulnerable products

    SOHO routers and potentially unmonitored enterprise networking equipment.

    Impact assessment

    The malware could lead to unauthorized data access, long-term persistence within the network, and potential bypass of security measures like EDR and network segmentation.

    Patches or workaround

    Recommendations include securing router interfaces, updating firmware, changing default credentials, and regularly rebooting routers to clear in-memory malware.

    Tags

    #Cuttlefish #ZeroClickMalware #RouterSecurity #NetworkHijacking #DataExfiltration

  11. Analysis of AcidRain Malware Variant "AcidPour" and Its Impact on Ukraine

    Date: 19 March 2022
    CVE: Not specified
    Sources: hackread.com/acidrain-linux-ma

    Issue Summary

    AcidRain, a destructive wiper malware, has been identified as a potential threat linked to the cyberattack on Viasat's KA-SAT satellite broadband service. This malware targets modems and routers, specifically designed to erase their storage contents, rendering the devices inoperable. The attack on Viasat disrupted communications across Ukraine and Europe, marking a significant cyber incident amidst the ongoing conflict between Russia and Ukraine.

    Technical Key findings

    AcidRain works by recursively deleting files and then attempting to destroy data on various storage devices, such as flash memory and SD/MMC cards, by overwriting them with up to 0x40000 bytes of data or using specific IOCTLS for erasure. This approach suggests a brute-force method, possibly indicating the attackers' desire for the tool to remain generic and reusable across different firmware. SentinelOne researchers found developmental and code overlaps with the VPNFilter malware, hinting at a connection to known Russian APT groups.

    Vulnerable products

    The attack mainly targeted satellite modems connected to the KA-SAT network, affecting thousands of modems across Europe. However, the malware's generic design suggests that it could potentially impact a wide range of routers and IoT devices with similar storage systems.

    Impact assessment

    The primary impact is the rendering of targeted modems and routers unusable, causing significant disruptions in satellite communications. This not only affects individual users but also has broader implications for organizations relying on satellite networks for their operations, including remote access to infrastructure and communications across Europe.

    Patches or workaround

    Specific patches or workarounds for AcidRain were not detailed in the sources. However, the fundamental mitigation involves securing network devices against unauthorized access and ensuring firmware is up to date to reduce vulnerabilities that could be exploited by similar malware.

    Tags

    #AcidRain, #AcidPour, #Ukraine, #ViasatAttack, #VPNFilter, #WiperMalware, #CyberSecurity, #RouterSecurity, #ModemWiper