AVM routers: another hole in the FritzBox remote maintenance function
Summary
In 2014 heise Security found a hole in the MyFritz apps for Android and iOS through which attackers could access a FritzBox’s web interface without a password. The apps did not check the box’s SSL certificate sufficiently, so an attacker on someone else’s network could grab the session ID. AVM solved this with certificate pinning: the apps remember the certificate’s fingerprint on first contact and warn if it changes.
Ideas
- Encryption without certificate checking does not protect against man-in-the-middle attacks.
- An intercepted session ID replaces the password.
- Every FritzBox runs its own certificate authority called localhost.
- Certificate pinning replaces the missing trusted CA.
Insights
- Self-signed certificates need a different trust anchor, otherwise HTTPS is ineffective.
- The first connection is the critical moment with the trust-on-first-use principle.
Facts
- With web access, an attacker could create their own user accounts and misuse telephony.
- The hole had nothing to do with the TR-069 problems being discussed at the same time.
- In early 2014 criminals had already exploited another FritzBox hole to make expensive phone calls via hijacked routers.
References
Critique
- The report comes from the discoverer itself and does not assess how many users actually administered their router from other people’s Wi-Fi networks.
Recommendations
- Set up pinned connections to your own infrastructure for the first time on your own trusted network.
- Reach router management remotely via a VPN rather than via an open web interface.
Links to the original source and the Web Archive open in a new tab.