Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


freitasm

BDFL - Memuneh
80944 posts

Uber Geek
+1 received by user: 41698

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

#154591 1-Nov-2014 14:10
Send private message

Some are really bad stuff:

Linksys SMART WiFi vulnerabilities


 

Overview

 

Linksys EA series routers running the Linksys SMART WiFi firmware contain multiple vulnerabilities.

Description

 

 

 

 

 

 

 

 

CWE-320: Key Management Errors - CVE-2014-8243

 

An unauthenticated attacker on the local area network (LAN) can read the router's .htpassword file by requestinghttp(s)://<router_ip>/.htpasswd. The .htpasswd file contains the MD5 hash of the administrator password.

CWE-200: Information Exposure - CVE-2014-8244

A remote, unauthenticated user can issue various JNAP calls by sending specially-crafted HTTP POST requests tohttp(s)://<router_ip>/JNAP/. Depending on the JNAP action that is called, the attacker may be able to read or modify sensitive information on the router.

It should also be noted that the router exposes multiple ports to the WAN by default. Port 100080 and 52000 both expose the administrative web interface to WAN users. Depending on the model, additional ports may be exposed by default as well.

 

 

 

Impact

 

 

 

 

 

 

 

 

A remote, unauthenticated attacker may be able to read or modify sensitive information on the router.

 

 

 

Solution

 

 

 

 

 

 

 

 

Apply an Update:

If possible, users are encouraged to update their firmware to the latest version to remediate these vulnerabilities. Linksys has provided the following fix versions:

 

 





Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 


Create new topic
timmmay
20923 posts

Uber Geek
+1 received by user: 5395

Trusted
Lifetime subscriber

  #1166467 1-Nov-2014 14:18
Send private message

Port 100080? Wow, they have more ports than anyone else!



Aredwood
3885 posts

Uber Geek
+1 received by user: 1749


  #1166620 1-Nov-2014 18:39

timmmay: Port 100080? Wow, they have more ports than anyone else!


They probally use it as a marketing feature. "You want the most ports? buy this router"

/joke





chevrolux
4962 posts

Uber Geek
+1 received by user: 2638
Inactive user


  #1166654 1-Nov-2014 20:18
Send private message

Yet another reason to not buy one of these terrible pieces of equipment.

They are seriously the biggest pieces of junk I have ever made the mistake of attempting to configure. Surprised Linksys still exists as a brand.

Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.