Article 4XVM8 Exploit that gives remote access affects ~200 million cable modems

Exploit that gives remote access affects ~200 million cable modems

by
Dan Goodin
from Ars Technica - All content on (#4XVM8)
netgear-cg3700e-800x554.jpg

Enlarge (credit: Netgear)

Hundreds of millions of cable modems are vulnerable to critical takeover attacks by hackers halfway around the world, researchers said.

The attacks work by luring vulnerable users to websites that serve malicious JavaScript code that's surreptitiously hosted on the site or hidden inside of malicious ads, researchers from Denmark-based security firm Lyrebirds said in a report and accompanying website. The JavaScript then opens a websocket connection to the vulnerable cable modem and exploits a buffer overflow vulnerability in the spectrum analyzer, a small server that detects interference and other connectivity problems in a host of modems from various makers. From there, remote attackers can gain complete control over the modems, allowing them to change DNS settings, make the modem part of a botnet, and carry out a variety of other nefarious actions.

Cable Haunt, as the researchers have named their proof-of-concept exploit, is known to work on various firmware versions of the following cable modems:

Read 12 remaining paragraphs | Comments

index?i=zZHgxUMtad0:oS9XJGeOq8Q:V_sGLiPB index?i=zZHgxUMtad0:oS9XJGeOq8Q:F7zBnMyn index?d=qj6IDK7rITs index?d=yIl2AUoC8zA
External Content
Source RSS or Atom Feed
Feed Location http://feeds.arstechnica.com/arstechnica/index
Feed Title Ars Technica - All content
Feed Link https://arstechnica.com/
Reply 0 comments