Critical security vulnerabilities in ASUS routers -- update immediately
#1
Exclamation 
Quote:Three ASUS Wi-Fi routers are vulnerable to three critically rated remote code execution vulnerabilities that can be exploited by malicious actors to take over the devices.

The affected wireless routers are the ASUS RT-AX55, RT-AX56U_V2 and the RT-AC86U router. All three models are still available on the ASUS website and at retailers.
  • The RT-AC86U is a dual-band gigabit Wi-Fi gaming router. It supports ASUS' AiMesh system and several other features designed to improve the gaming experience or security.
  • The RT-AX55 is a dual-band WiFi 6 router that is also supporting ASUS' AiMesh WiFi system.
  • The RT-AX56U_V2 is a high-end dual-band WiFi 6 gaming router that is compatible with Sony's PS5, supports Mesh WiFi and various other gaming related features, including a gaming port.
The three vulnerabilities have a CVSS rating of 9.8 out of 10. It is one of the highest ratings and explained by the nature of the security issues. All three vulnerabilities are so-called format string vulnerabilities.

It means, in this particular case, that malicious actors may take over the ASUS router remotely and without authentication. All it takes for that is to send a specially crafted instruction to the vulnerable device, which would provide the attacker with control over it.

This type of vulnerability may be caused by improper validation of instructions, e.g., user input.

The vulnerabilities and patchesThe routers are affected by the following three vulnerabilities: The links do not provide a wealth of information on the issues, only that all three are input format string vulnerabilities in the API module ‘ser_iperf3_svr.cgi’ and general setting function.

ASUS has published updates for all three affected routers. Owners of the devices may want to install the firmware updates immediately to protect their devices against potential attacks that target the issues.

Here are the relevant links:
  • RT-AX55 -- Download and install the latest firmware update from the ASUS website. At the time of writing, it is version 3.0.0.4.386_52041, released on August 31, 2023. It will be replaced by newer updates eventually, which should then be installed.
  • RT-AX56U -- The latest firmware update is version 3.0.0.4.386.51665, released May 18, 2023. It is unclear if this addresses the issue, as the CVE lists 3.0.0.4.386_51948 as the minimum version.
  • RT-AC86U - The firmware update 3.0.0.4.386_51915 addresses the reported security issues.
Users who use one of the three ASUS routers may want to install the latest firmware on their device to protect it from potential attacks.

Bleeping Computer, which reported the issue first, also recommends disabling remote administration capabilities, if not required, which should prevent future remote attacks against the router.

Now You: which router(s) do you use, and why?
...
Continue Reading
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Find out if an USB device is fake with f...
Fake USB devices c...harlan4096 — 08:47
Windows 11 KB5048685 Update causes Wi-Fi...
The KB5048685 Upda...harlan4096 — 12:36
Windows 11: issue may prevent further in...
The latest version...harlan4096 — 08:47
Notepad++ v8.7.5 (2024-12-25)
Notepad++ v8.7.5 (...harlan4096 — 08:16
AdGuard for Mac 2.16.2
AdGuard for Mac 2....harlan4096 — 08:13

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
There are no staff members currently online.

>