Critical vulnerability affecting millions of modems discovered

Many brands offer the ability to share the USB devices installed in their modem and router models over the network. Security researchers have developed a tool for sharing devices over the network. KCodes in NetUSB module discovered a critical vulnerability.

Netgear, TP-Link, Tenda, EDiMAX and D-Link USB devices can be used in routers and modems produced by many companies. Operations carried out thanks to the Linux kernel module called KCodes NetUSB provide users with access to external hard disks, flash memory and printers over the network.


Joint reaction from major operators to Apple’s privacy feature

Four major operators based in Europe said the iCloud Private Pass feature will undermine Europe’s digital sovereignty.

Critical vulnerability found in modems with USB ports

CVE-2021-45608 vulnerability published with code, buffer overflow It is done with a type of attack called. When the operation is successful, attackers have the authority to remotely execute code on the vulnerable device.

Critical vulnerability found in modems with USB ports

CVE-2021-45608, the last of the security vulnerabilities discovered in NetUSB in recent years, draws attention with its similarity to the CVE-2015-3036 vulnerability published in May 2015. Hackers were able to access devices with the buffer overflow method in the vulnerability that emerged in 2015. denial-of-service (DoS) It can attack or run code.

Netgear announced that it has closed the security vulnerability, which has a very high security risk, with the update it released for some models. Other manufacturers have not yet made a statement on the subject. It is worth remembering that modem and router manufacturers usually do not release updates to their old models.

List of Netgear models and firmware versions where the vulnerability was closed:

  • D7800 firmware version 1.0.1.68 on model
  • R6400v2 1.0.4.122 firmware version on model
  • R6700v3 1.0.4.122 firmware version on model

Max Van Amerongen, a security researcher, said, “As the discovered is in an open licensed module, the only solution is to install the updates released by the companies. You should make sure that you are not using an expired modem/router for software support.” used the phrases.

source site-28