Customs Today
  • Home
  • Islamabad
  • Karachi
  • Lahore
  • National
  • Transfers and Postings
  • Chambers & Associations
  • Business
No Result
View All Result
Customs Today
  • Home
  • Islamabad
  • Karachi
  • Lahore
  • National
  • Transfers and Postings
  • Chambers & Associations
  • Business
No Result
View All Result
Customs Today
No Result
View All Result
Home Science & Technology Technology

Misfortune Cookie affects 12m low-end SOHO routers including D-Link, Edimax, Huawei

byMonitoring Report
20/12/2014
in Technology
Share on FacebookShare on Twitter

LONDON: More than 12 million low-end SOHO routers worldwide are affected by the bug, dubbed Misfortune Cookie. At least 200 different models of devices from various manufacturers and brands are vulnerable, it’s claimed, including kit from D-Link, Edimax, Huawei, TP-Link, ZTE, and ZyXEL.

Anything connected to the network Cs, phones, tablets, printers, security cameras, refrigerators, or any other networked device is at risk from attack within that LAN, if a vulnerable router is compromised.

You might also like

Tesla driverless system to use updated radar technology

12/09/2016

Apple to develop its own self-driving technology

10/09/2016

An attacker exploiting the Misfortune Cookie flaw could monitor victims’ web browsing, screw around with DNS, steal account passwords and sensitive data, infect other machines with malware, or control devices. According to Check Point:

Attackers can send specially crafted HTTP cookies [to the gateway] that exploit the vulnerability to corrupt memory and alter the application and system state. This, in effect, can trick the attacked device to treat the current session with administrative privileges to the misfortune of the device owner.

The affected software, it is told, is the web server RomPager from AllegroSoft, which is typically embedded in the firmware in router and gateway devices. The HTTP server provides the web-based user-friendly interface for configuring the products.

To close the security hole, CVE-2014-9222, one must patch the device’s firmware assuming this is even possible and user manufacturer has released an update. AllegroSoft apparently fixed the bug in 2005, but the corrected code has yet to make it into routers in homes and offices. The programming blunder was introduced in 2002 when the biz distributed the software to manufacturers, it’s claimed.

Even if the gateway is configured to not expose its builtin web server to the wider internet, many devices listen publicly on port 7547 to receive instructions from ISPs via the TR-069 or Customer Premises Equipment WAN Management Protocol allowing hackers to send a malicious cookie from far away to that port and hit the vulnerable server software.

One workaround would be to make sure users gateway or router’s web server is not open to the public on ports 80, 8080, 443, 7547, and possibly others. According to Check Point:

Tags: 12 million low-end SOHO routers worldwideEdimaxHuaweiincluding kit from D-LinkMisfortune Cookie flaw affects

Related Stories

Tesla driverless system to use updated radar technology

byCT Report
12/09/2016

WASHINGTON: Electric carmaker Tesla announced Sunday it was upgrading its Autopilot software to use more advanced radar technology. In a...

Apple to develop its own self-driving technology

byCT Report
10/09/2016

SAN FRANCISCO: Apple may not become an automaker, but it still wants to develop its own self-driving technology. The iPhone-maker's...

‘YouTubers’ outshining old-school television

byCT Report
09/08/2016

SAN FRANCISCO: A media revolution is taking place, and most people over 35 years of age aren’t tuned in. Millennial...

Google pays tribute to Edhi

byCT Report
11/07/2016

ISLAMABAD: The technology giant, Google, has paid tribute to renowned social activist, philanthropist and humanitarian Abdul Sattar Edhi by placing...

Next Post

Ireland 4th best country in world to do business

  • Terms and Conditions
  • Disclaimer

© 2011 Customs Today -World's first newspaper on customs. Customs Today.

No Result
View All Result
  • Transfers and Postings
  • Latest News
  • Karachi
  • Islamabad
  • Lahore
  • National
  • Chambers & Associations
  • Business
  • About Us

© 2011 Customs Today -World's first newspaper on customs. Customs Today.