Russian security researcher Timur Yunusov has discovered several critical (Zero Day) vulnerabilities in 3G and 4G routers and modems using devices from Huawei, ZTE, Gemtek, and Quanta. The vulnerabilities allow attackers to compromise the devices with simple SMS messages as well as via HTTP connections.
The research and Zero Days were first presented in detail in December to hackers attending the Nullcon conference in Goa and revealed unpatched security vulnerabilities from eight devices from the above companies.
Timur Yunusov, a consultant at Positive Technologies, discovered that modems and routers from Gemtek, Quanta, and ZTE are exposed on Shodan.
“All the models contained critical vulnerabilities,” Yunusov says. “We could essentially exploit all the vulnerabilities remotely.”
Four of the eight modems and routers contain cross-site scripting vulnerabilities that allow system infection, SMS interception, and victim location tracking.

“Since we can infiltrate a modem … we can also infect the computer that the device is connected to, which gives us many ways to intercept the computer’s data.”
It should be mentioned that Yunusov and his team showed us last year how an SMS could be used to gain access to railway systems and derail trains.
