Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror
×
Networking Security Hardware IT

Remote Linksys 0-Day Root Exploit Uncovered 133

Orome1 writes "DefenseCode researchers have uncovered a remote root access vulnerability in the default installation of Linksys routers. They contacted Cisco and shared a detailed vulnerability description along with the PoC exploit for the vulnerability. Cisco claimed that the vulnerability was already fixed in the latest firmware release, which turned out to be incorrect. The latest Linksys firmware (4.30.14) and all previous versions are still vulnerable."
This discussion has been archived. No new comments can be posted.

Remote Linksys 0-Day Root Exploit Uncovered

Comments Filter:
  • Zero day? (Score:5, Insightful)

    by arth1 ( 260657 ) on Monday January 14, 2013 @05:48PM (#42585831) Homepage Journal

    What's zero-day about this exploit?
    It was found during testing, and there are no exploits in the wild.

    As such it fails BOTH tests for being a zero day exploit:
    - The company must not know the details of the exploit
    - It must be in the wild

    Stop using the phrase "zero day" about just any exploitable bug. Call them security vulnerabilities, which is what they are.

  • Re:WRT54GL (Score:5, Insightful)

    by NatasRevol ( 731260 ) on Monday January 14, 2013 @06:42PM (#42586391) Journal

    Anyone running stock on a WRT54GL deserves to be hacked.

    That's one of the dumber arguments I've ever seen on Slashdot.

  • Re:WRT54GL (Score:5, Insightful)

    by Barryke ( 772876 ) on Monday January 14, 2013 @07:18PM (#42586759) Homepage

    The market for WRT54GL is there because of people buying it to put their own firmware on.

  • Re:WRT54GL (Score:3, Insightful)

    by Anonymous Coward on Monday January 14, 2013 @07:43PM (#42587009)

    You say DDWRT, I say Tomato.

  • Re:Zero day? (Score:2, Insightful)

    by Anonymous Coward on Monday January 14, 2013 @07:48PM (#42587039)

    In fact I bet 95% of affected routers have the default web interface password anyway.

    Yes, with the user/pass as admin/password or admin/admin! :-0

  • Re:WRT54GL (Score:5, Insightful)

    by dutchwhizzman ( 817898 ) on Tuesday January 15, 2013 @01:42AM (#42588957)
    You are forgetting that a lot of people bought it because "the guy that knows computers" said it was "the best model", never understanding why and how to take advantage of the added value of the GL over the budget model. The amount of home computer equipment that gets bought on recommendation of either the sales guy, the neighbour kid or the relative that works in IT is staggeringly high. Those people will most likely still be running stock firmware, probably a relic version at that.

You knew the job was dangerous when you took it, Fred. -- Superchicken

Working...