Verizon Issues Fix for Home Router Bugs
#1
Quote:Customers using the Verizon FiOS Quantum Gateway for their home routers are advised to update to the latest firmware – version 02.02.00.13 – which addresses fixes for multiple vulnerabilities discovered by Chris Lyne, researcher at Tenable Research.
 
According to an advisory published today, a new vulnerability (CVE-2019-3914) was found in the administrator password, not the password users enter to login. Lyne discovered that the vulnerability would allow an attacker to authenticate remote command injection. His tinkering led him to discover additional vulnerabilities, which include login replay (CVE-2019-3915) and password salt disclosure (CVE-2019-3916).
 
Lyne proposed several different scenarios in which a malicious actor could tamper with the security settings of the device, but in CVE-2019-3914, the attacker “must be authenticated to the device's administrative web application in order to perform the command injection. In most cases, the vulnerability can only be exploited by attackers with local network access. However, an internet-based attack is feasible if remote administration is enabled; it is disabled by default.”
 
While the first vulnerability requires that an attacker be authenticated, in the login replay flaw, the web administration interface does not enforce HTTPS. As a result, “an attacker on the local network segment can intercept login requests using a packet sniffer. These requests can be replayed to give the attacker admin access to the web interface. From here, the attacker could exploit CVE-2019-3914.”

SOURCE: https://www.infosecurity-magazine.com/ne...me-router/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
How I Use Stag VPN for Android Developme...
Hi everyone, As an ...auroralane7754 — 14:09
dGuard Browser Extension 5.1.119 (MV3 st...
AdGuard Browser Ex...harlan4096 — 08:48
Schrödinger’s antivirus: is protection d...
How the research t...harlan4096 — 08:47
AV-Comparatives: Business Security Test ...
The first half-yea...harlan4096 — 08:45
Microsoft reveals when Windows 10 custom...
With Windows 10 re...harlan4096 — 08:39

[-]
Birthdays
Today's Birthdays
avatar (45)RidgeDimb
Upcoming Birthdays
avatar (42)lapedDow
avatar (48)rituabew
avatar (36)omyjul
avatar (40)papedDow
avatar (49)ArnoldFum
avatar (37)yfaza
avatar (48)Kevensi
avatar (38)boineDon
avatar (39)Grompelbawn
avatar (40)vkseogaF
avatar (36)usogy
avatar (39)ywixazok
avatar (37)ixoqe
avatar (35)pa.OpenTran

[-]
Online Staff
There are no staff members currently online.

>