HomeSecurityLinksys vulnerability confirmed as an HNAP1 bug

Linksys vulnerability confirmed as an HNAP1 bug

2013_Linksys_Logo

A worm called “The Moon” that began spreading among Linksys broadband kits last week has been confirmed to be a vulnerability in the HNAP1 implementation on the devices, and an exploit has been made public.

The exploit was posted on Exploit-db.com by user Rew, who said that this Reddit discussion means "the cat is out of the bag.".

Potentially vulnerable devices include the Linksys E4200, E3200, E3000, E2500, E2100L, E2000, E1550, E1500, E1200, E1000 and E900, according to the SANS Institute, which first identified the worm. The SANS Institute also notes that the vulnerability depends on the firmware revision.

Unfortunately, some of the devices on the list are no longer supported, so users cannot get the new firmware (for example, as El Reg noted last week, the E1000 is on the unsupported list).

HNAP – the Home Network Administration Protocol – was created by Pure Networks and acquired by Cisco, which provides admin access to the HNAP kit.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS