Security News

Cisco SMB kit harbors cross-site scripting bug: One wrong link click... and that's your router pwned remotely
2020-07-02 13:00

Cisco has patched a cross-site scripting vulnerability in two VPN routers it sells to small businesses and branch offices. By default, the management feature is disabled for remote users, though it is enabled for people on the same LAN. "A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information," Cisco explained in its advisory yesterday.

Living on a prayer? Netgear not quite halfway there with patches for 28 out of 79 vulnerable router models
2020-06-30 18:28

Netgear has now patched 28 out of 79 vulnerable router models, six months after infosec researchers first noticed security problems potentially allowing an attacker to remotely execute code as root. Over the past few weeks Netgear has been pushing out fixes, having so far plugged problems with 28 of the 79 models it says are affected by the unwanted remote-superuser flaw.

Netgear Zero-Day Allows Full Takeover of Dozens of Router Models
2020-06-19 13:05

UPDATED. Researchers this week said they discovered an unpatched, zero-day vulnerability in firmware for Netgear routers that put 79 device models at risk for full takeover, they said. The flaw, a memory-safety issue present in the firmware's httpd web server, allows attackers to bypass authentication on affected installations of Netgear routers, according to two separate reports: One on the Zero Day Initiative by a researcher called "d4rkn3ss" from the Vietnam Posts and Telecommunications Group; and a separate blog post by Adam Nichols of cybersecurity firm Grimm.

Cisco Webex, Router Bugs Allow Code Execution
2020-06-18 16:18

Cisco is warning of three high-severity flaws in its popular Webex web conferencing app, including one that could allow an unauthenticated attacker to remotely execute code on impacted systems. "An attacker could exploit this vulnerability by sending crafted requests to a vulnerable Cisco Webex Meetings or Cisco Webex Meetings Server site," according to Cisco's security update.

WFH Alert: Critical Bug Found in Old D-Link Router Models
2020-06-15 19:11

D-Link is urging customers to replace its now obsolete line of DIR-865L Wireless Routers in reaction to a recently discovered critical command-injection bug that leaves users open to a denial-of-service attack. "The vulnerabilities were found in the DIR-865L model of D-Link routers, which are meant for home network use," researchers wrote.

WFH Alert: Critical Bug Found in Old D-Link Router Models
2020-06-15 19:11

D-Link is urging customers to replace its now obsolete line of DIR-865L Wireless Routers in reaction to a recently discovered critical command-injection bug that leaves users open to a denial-of-service attack. "The vulnerabilities were found in the DIR-865L model of D-Link routers, which are meant for home network use," researchers wrote.

Cisco Patches Dozen Vulnerabilities in Industrial Routers
2020-06-04 12:13

Cisco this week announced that it has patched tens of vulnerabilities in its IOS software, including a dozen security flaws that impact the company's industrial routers and switches. A dozen vulnerabilities appear to impact the company's industrial products.

Cisco plugs bucketful of security holes in industrial routers, switches
2020-06-04 12:01

Cisco has fixed more than two dozen critical and high-severity security vulnerabilities affecting operating systems running on the company's carrier-grade and industrial routers and switches. Cisco IOS - a family of network operating systems used on many Cisco Systems routers and network switches.

Tools Used in GhostDNS Router Hijack Campaigns Dissected
2020-05-21 16:24

GhostDNS is used to compromise a wide range of routers to facilitate phishing - perhaps more accurately, pharming - for banking credentials. Malvertising allows the EK to directly attack the router from a computer that uses the router.

High-Severity Cisco IOS XE Flaw Threatens SD-WAN Routers
2020-04-29 20:37

The flaw exists in Cisco IOS XE. This Linux-based version of Cisco's Internetworking Operating System is used in Cisco software-defined wide area network routers. In March, Cisco issued 24 patches tied to vulnerabilities in its IOS XE operating system.