bk99.de entertain the web since 1997

A hidden router interface on TCP port 32764

Summary

Eloi Vanderbeken analyses an unknown service in home routers that can read out configurations and execute arbitrary commands with root privileges. The service used TCP port 32764. Devices from several brands were affected.

Ideas

  • A proprietary service listens on a fixed TCP port.
  • Reverse engineering reconstructs the message format and the available commands.
  • The interface reads the router configuration including credentials.
  • One command starts arbitrary programs with the highest privileges.

Insights

  • Undocumented maintenance access becomes a permanent attack surface.
  • Network segmentation limits the damage done by insecure embedded devices.
  • Checking firmware needs binary analysis and runtime tests together.

Facts

  • The analysis code was published on GitHub.

Recommendations

  • Block management access from untrusted networks.
  • Replace routers that are no longer maintained or install free firmware.

References

Read the original article

Search the Web Archive