HomeSecurityKCodes NetUSB bug: Affects millions of routers from different vendors

KCodes NetUSB bug: Affects millions of routers from different vendors

A high-impact vulnerability that allows remote code execution has affected millions of end-user router devices.

See also: Uber: Ignores vulnerability that allows sending emails from Uber.com

KCodes NetUSB
KCodes NetUSB bug: Affects millions of routers from different vendors

On Tuesday, SentinelOne published an analysis of the bug, which was tracked as CVE-2021-45388 and rated as critical by the research team.

The vulnerability affects the KCodes NetUSB kernel module. KCodes solutions are licensed by many hardware vendors to provide USB over IP functionality in products such as routers, printers, and flash storage devices.

See also: Log4j Log4Shell vulnerability used to install Dridex banking trojan

KCodes NetUSB, the subject of SEC Consult Vulnerability Lab analysis in the past, is proprietary software used to facilitate these connections – and the software is currently “used by a large number of network device vendors,” whose security flaws “affect millions of end-user router devices,” according to SentinelOne.

Researcher Max Van Amerongen discovered the flaw while examining a Netgear device. The kernel module, NetUSB, did not properly validate the size of packets retrieved over remote connections, allowing a possible heap buffer overflow.

According to Amerongen, although it would be difficult to write a malicious payload to trigger CVE-2021-45388 due to coding limitations, an exploit could lead to remote code execution in the kernel.

KCodes NetUSB
KCodes NetUSB bug: Affects millions of routers from different vendors

SentinelOne says that vendors including Netgear, TP-Link, DLink and Western Digital have licensed the software and are now all aware of the security flaw.

See also: TellYouThePass ransomware exploits Log4Shell vulnerability

The researchers revealed their findings to KCodes on September 9th, as it made more sense to inform the source who could then distribute a patch to everyone rather than just updating Netgear based on a single product test. A proof-of-concept patch was made available on October 4th and was sent to all vendors on November 17th.

Firmware updates , such as those detailed in the warning issued by Netgear, have either been issued or are in progress.

As of this writing, no exploit of the bug has been discovered.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS