Slashdot Mirror


Remote Linksys 0-Day Root Exploit Uncovered

Orome1 writes "DefenseCode researchers have uncovered a remote root access vulnerability in the default installation of Linksys routers. They contacted Cisco and shared a detailed vulnerability description along with the PoC exploit for the vulnerability. Cisco claimed that the vulnerability was already fixed in the latest firmware release, which turned out to be incorrect. The latest Linksys firmware (4.30.14) and all previous versions are still vulnerable."

8 of 133 comments (clear)

  1. WRT54GL by markdavis · · Score: 5, Informative

    Yes, you would think the summary would at LEAST say *WHICH* router it affects, since Linksys has lots of different models. It is the WRT54GL.

    I *love* that router and have probably 30 of them. Low power draw, real antenna, wall mountable, etc. My recommendation- install Toastman Tomato on it. They never crash, freeze, freak out, not work with certain devices, etc. Rock solid stuff.

    Strangely, the WRT54GL is STILL BEING SOLD!

    1. Re:WRT54GL by Synerg1y · · Score: 4, Informative

      People still run their 54gl's stock???

      Repeat after me: d-d--w-r-t

      Turns your router into something more like one of those fancy enterprise cisco routers. The 54gl is dd-wrt's 1st platform I believe (too lazy to look it up), so compatibility is bound to be around 100%.

    2. Re:WRT54GL by VValdo · · Score: 5, Informative

      I agree it's bad form not to put the router models in the summary. But from the press release...

      Exploit shown in this video has been tested on Cisco Linksys WRT54GL, but other Linksys versions/models are probably also affected.

      (emphasis mine)

      Incidentally, re: the GL model of the Linksys-- the "L" I'm pretty sure stands for Linux, and was the model that was in response to everyone reinstalling dd-wrt and other firmware...

      --
      -------------------
      This is my SIG. There are many like it, but this one is mine.
    3. Re:WRT54GL by Lothsahn · · Score: 4, Informative

      I love Tomato too--in fact, I use it at my house. However, Tomato was originally based off Stock Linksys, and might also be affected. Until full disclosure occurs, we'll not know for sure.

      --
      -=Lothsahn=-
  2. Re:Remote? by Amouth · · Score: 4, Informative

    that is far more difficult to do than if the exploit works on the WAN side.

    --
    '...if only "Jumping to a Conclusion" was an event in the Olympics.'
  3. Re:WRT54GL? by Baloroth · · Score: 4, Informative

    Just gotta ask: have they tried it on any OTHER models? Because that's an OLD OLD router that shouldn't even be running cisco/linksys firmware anymore.

    If by "OLD OLD" you mean "is still produced, sold, and obviously supported, and can be purchased on Newegg right this second with stock firmware" then sure. It's an extremely common router, even among the non-techie crowd, so I wouldn't be surprised if the majority of them are still on stock firmware.

    --
    "None can love freedom heartily, but good men; the rest love not freedom, but license." --John Milton
  4. Public Service Announcement by Raystonn · · Score: 5, Informative

    Unless you have remote administration enabled, this exploit is only achievable from a system within the local network. This attack is not an internet threat.

  5. Re:WRT54GL watch out for openwrt by shoor · · Score: 4, Informative

    Recent openwrt distros have a problem with the classic wrt54gl in that it doesn't have enough memory. I know because it happened to me. It installs, but when you try to change configuration, it bricks and you need to ground pin 15 to get it to reflash something. From the openwrt site:

    "In a test with OpenWrt 10.03.1-rc6, the OS will install but LuCI will be unable to update settings because there isn't enough flash left free."

    Old enough versions should work, but I'm happy with my tomato install.

    --
    In theory, theory and practice are the same; in practice they're different. (Yogi Berra & A. Einstein)