Please Apply Our 10 Year-Old Patch: The Dismal State of Embedded Device Security
ID: 93b32c86-fac8-5307-8ef6-769d4a2047db
STIX ID: report--93b32c86-fac8-5307-8ef6-769d4a2047db
Feed Name: Security Ledger
The article details the “Misfortune Cookie” vulnerabilities (CVE-2014-9222 and CVE-2014-9223) in the Rom Pager embedded web server found in an estimated 12 million consumer broadband routers from vendors such as Linksys, D-Link, Huawei, TP-Link, ZTE and Edimax; it describes how specially crafted HTTP cookies can grant administrative privileges to attackers (enabling DNS hijacking or botnet enlistment) and highlights that although a patch exists, many manufacturers did not distribute firmware updates, leaving large numbers of devices vulnerable.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
