HomeSecurityOpenWrt Sysupgrade flaw allows malicious firmware images

OpenWrt Sysupgrade flaw allows malicious firmware images

A flaw in OpenWrt 's Attended Sysupgrade feature , which is used to create custom firmware images on demand, could have allowed the distribution of malicious firmware packages.

See also: CapibaraZero Firmware: New innovation in Open-Source technology

OpenWrt flaw

OpenWrt is a highly customizable, open-source, Linux-based operating system designed for embedded devices, particularly network devices such as routers, access points, and other IoT hardware. The project is a popular alternative to specific firmware , as it offers many advanced features and supports routers from ASUS, Belkin, Buffalo, D-Link, Zyxel, and many others.

The command injection and fragmentation flaw in OpenWrt was discovered by Flatt Security researcher “RyotaK” during a routine upgrade of a home lab router. The critical flaw (CVSS v4 score: 9.3), identified as CVE-2024-54143, was patched within hours of being disclosed to the OpenWrt developers. However, users are urged to perform checks to ensure the security of their installed firmware.

OpenWrt includes a service called Attended Sysupgrade, which allows users to create custom, on-demand firmware versions that include previously installed packages and settings.

See also: New AirPods Pro 2 firmware is available for iOS 18.1 hearing health features.

RyotaK discovered that the sysupgrade.openwrt.org processes these inputs via commands running in a container environment.

OpenWrt Sysupgrade flaw allows malicious firmware images

A flaw in OpenWrt's input handling mechanism, stemming from the unsafe use of the 'make' command in server code, allows arbitrary command injection via package names.

A second issue RyotaK discovered was that the service uses a truncated 12-character SHA-256 to cache build artifacts, limiting the hash to only 48 bits. The researcher explains that this makes brute-forcing collisions possible, allowing an attacker to create a request that reuses a cache key found in legitimate firmware versions.

By combining the two problems and using the Hashcat on an RTX 4090, RyotaK showed that it is possible to modify firmware artifacts to deliver malicious versions to unsuspecting users.

See also: New Firmware Version for the USB-C Apple Pencil: What's Changing?

Malicious firmware refers to attacks that aim to install malicious software on devices or systems, compromising security and causing serious consequences. Malicious firmware can include hidden programs, viruses, or even attacks that violate users' privacy and security. Detecting and eliminating malicious firmware is crucial to maintaining system security and protecting users' personal data. Companies and users must be vigilant and take preventive measures to prevent the installation of malicious firmware and ensure the security of their systems and data.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS