HomeSecurityHackers compromise private routers - List of vulnerable devices

Hackers are compromising private routers – List of vulnerable devices

Is your network lagging lately? You may belong to the Mirai botnet that has been ongoing lately by hackers who are breaching private routers!

Hackers recently exploited a critical authentication bypass vulnerability that affects home routers (routers) with Arcadyan firmware, with the aim of gathering a strong fleet of bots by creating the Mirai botnet, which will then be used for malicious activities.

See Also: Linux version of BlackMatter ransomware targets VMware ESXi servers

Hackers breach private routers - List of vulnerable devices
Hackers private routers: Why they breach home routers?

The vulnerability identified as CVE-2021-20090 is a path traversal (score: 9.9/10) vulnerability in the web interfaces of routers that have Arcadyan firmware, which could allow hackers to bypass device authentication.

The vulnerability was discovered by researchers at Juniper Threat Labs and is one of many that have been disclosed recently, targeting IoT devices.

Millions of routers exposed to attacks

Among the vulnerable devices we find dozens of router models from many manufacturers and ISPs, including Asus, British Telecom, Deutsche Telekom, Orange, O2 (Telefonica), Verizon, Vodafone, Telstra and Telus.

Based on the extensive list of manufacturers affected by this security flaw, the total number of devices exposed to attacks likely reaches millions of routers.

See Also: BadAlloc bugs expose millions of IoT devices to hijack

Informationally, the security vulnerability was discovered by Tenable, which published a security advisory on April 26, and this month – Tuesday August 3 – added the proof of concept exploit code.

"The security flaw in Arcadyan's firmware has existed for at least 10 years and therefore affects at least 20 models across 17 different vendors," Evan Grant, Tenable Staff Research Engineer, said last Tuesday.

Here follows a list of all known devices and manufacturers affected by the CVE-2021-20090 security bug:

Hackers breach private routers - List of vulnerable devices
List of vulnerable devices

Attacks start two days after the PoC exploit release

Last week, Juniper Threat Labs detected some attack patterns attempting to exploit the vulnerability which originates from an IP address in Wuhan, China.

See also: Angry Conti ransomware associate leaks information

The hackers behind this hacking campaign are using malicious tools to develop a variant of the Mirai botnet, similar to those used in an earlier Mirai campaign that targeted IoT and network security devices.

hacker - ID photos
Hackers private routers: Why they breach home routers?

"The similarity could suggest that the attacks are the work of the same hacking group that aims to upgrade its arsenal," said a spokesperson for Juniper Threat Labs.

See Also: How safe is Apple's new method for abused children?

It is worth mentioning that given that most people may not even know the magnitude of the risk and will not upgrade their device soon, this attack tactic can be very successful, cheap, and easy to execute.

Indicators of compromise (IOCs) including IP addresses used to carry out the attacks as well as sample hashes are available at the end of the Juniper Threat Labs report.

Source of information: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS