OpenWrt Sysupgrade flaw let hackers push malicious firmware images
ID: 75d3b2e2-b09c-57b5-8fc8-4ceded2bf9e6
STIX ID: report--75d3b2e2-b09c-57b5-8fc8-4ceded2bf9e6
Feed Name: Bleeping Computer
A Flatt Security researcher discovered a critical OpenWrt vulnerability (CVE-2024-54143) in the Attended Sysupgrade service that combined command injection via package names with a 12-character truncated SHA-256 cache key, enabling an attacker to craft cache collisions and deliver malicious custom firmware. OpenWrt took the service offline, patched the flaw within hours, and found no evidence of exploitation; users are advised to reinstall newly generated images and update any self-hosted ASU instances to eliminate residual risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
