Verizon Issues Fix for Home Router Bugs
#1
Quote:Customers using the Verizon FiOS Quantum Gateway for their home routers are advised to update to the latest firmware – version 02.02.00.13 – which addresses fixes for multiple vulnerabilities discovered by Chris Lyne, researcher at Tenable Research.
 
According to an advisory published today, a new vulnerability (CVE-2019-3914) was found in the administrator password, not the password users enter to login. Lyne discovered that the vulnerability would allow an attacker to authenticate remote command injection. His tinkering led him to discover additional vulnerabilities, which include login replay (CVE-2019-3915) and password salt disclosure (CVE-2019-3916).
 
Lyne proposed several different scenarios in which a malicious actor could tamper with the security settings of the device, but in CVE-2019-3914, the attacker “must be authenticated to the device's administrative web application in order to perform the command injection. In most cases, the vulnerability can only be exploited by attackers with local network access. However, an internet-based attack is feasible if remote administration is enabled; it is disabled by default.”
 
While the first vulnerability requires that an attacker be authenticated, in the login replay flaw, the web administration interface does not enforce HTTPS. As a result, “an attacker on the local network segment can intercept login requests using a packet sniffer. These requests can be replayed to give the attacker admin access to the web interface. From here, the attacker could exploit CVE-2019-3914.”

SOURCE: https://www.infosecurity-magazine.com/ne...me-router/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Free Download Manager 6.34.1.6907
Changes in 6.34.1....harlan4096 — 07:25
Waterfox 6.6.14
Waterfox 6.6.14 ...harlan4096 — 07:24
Adlice Protect (formerly RogueKiller) 16...
V16.6.2 06/02/2026...harlan4096 — 07:23
Opera 148.0.7778.180
Hello! New upda...harlan4096 — 07:20
AMD Radeon Software Adrenalin 26.6.1 dri...
AMD Radeon Softwar...harlan4096 — 07:17

[-]
Birthdays
Today's Birthdays
avatar (50)eapedDow
avatar (47)Carlosskake
Upcoming Birthdays
avatar (42)tapedDow
avatar (48)BrantgoG
avatar (49)rapedDow
avatar (44)Johnsonsyday
avatar (49)Groktus
avatar (41)efodo
avatar (39)Tedscolo
avatar (46)brakasig
avatar (51)smudloquask
avatar (46)benchJem
avatar (45)JamesReshy
avatar (47)Francisemefe
avatar (40)leoniDup
avatar (39)Patrizaancem
avatar (39)biobdam
avatar (42)zacforat
avatar (47)NemrokReks
avatar (50)Jasoncedia
avatar (38)Barrackleve
avatar (40)Julioagopy
avatar (50)aolaupitt2558
avatar (48)vadimTob
avatar (38)leannauu4
avatar (40)storoBox
avatar (48)kinotHeemn
avatar (39)Ceballos1976
avatar (40)efynu
avatar (32)horancos

[-]
Online Staff
There are no staff members currently online.

>