ARN

Is your Linksys or Netgear router open to attack?

Basically, if you're logged into the router as an admin while you visit a seemingly benign site that contains a malicious cross-site request forgery, they can do all kinds of nasty stuff

If you have a Linksys model WRT160N or Netgear RP614v4 router, it may be time to worry a little. At least according to a report out of Defcon from The Register. The vulnerability is based on CSRF, or cross-site request forgery, an issue with the cPanel web-based control software used to administrate the devices.

Basically, if you're logged into the router as an admin while you visit a seemingly benign site that contains a malicious cross-site request forgery, they can do all kinds of nasty stuff. They can change your admin login, load custom firmware, or change basically any setting they want.

cPanel is a fairly popular web-based hosting application, and of course companies like Linksys and Netgear often use similar code across a product line, so there may be quite a few other products compromised - the two mentioned above are just the two singled out by the security researchers.

Will it get fixed? Probably not. Researcher Mike Bailey is quoted saying, "The response I got from cPanel was we can't fix this because it's a feature. Apparently, they're worried it's going to break integration with third party billing software, so they can't fix this."

So if you use cPanel to administer your web site or router, for starters, only ever log in when you're not visiting any other websites and log out fully before you do anything else. The Register has more...

Follow Jason Cross on Twitter or visit his site.

Come socialise with us! Facebook | LinkedIn

More about: Linksys, Netgear
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the ARN comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: Defcon, Linksys, netgear
ARN Directory | Distributors relevant to this article
Express Online , Leader Computers , Multimedia Technology
rhs_login_lockGet exclusive access to ARN's news, research and invitation only events.
ARN Distributor Directory
ARN Vendor Directory

iAsset is a channel management ecosystem that automates all major aspects of the entire sales,marketing and service process, including data tracking, integrated learning, knowledge management and product lifecycle management.