Wi-Fi routers targeted by hackers
Summary
According to Trend Micro, unauthorised login attempts on home routers rose from 23 to 249 million between September and December 2019. Attackers want to take over the devices by brute force and integrate them into botnets for DDoS attacks, especially as more company data moved into home offices. An analysis of 127 routers by Fraunhofer FKIE also showed that many had not received updates for years and ran on very old Linux kernels.
Ideas
- The router is the first device of the home network reachable from the internet.
- Hijacked routers serve as a bridgehead to IoT devices behind them.
- Many manufacturers do not provide security updates for older models.
- Exploit mitigations were missing in many firmware images.
Insights
- Working from home turns the security of private routers into a company matter.
- The age of the built-in kernel is a good indicator of how well firmware is maintained.
Facts
- For 22 of the 127 devices tested there had been no firmware update for two years.
- More than a third of the firmware used kernels without security updates for at least nine years.
- AVM routers performed best by far in the Fraunhofer test.
- In July 2020 the BSI published a test specification for certifying home routers according to its technical guideline.
References
Critique
- The attack figures come from an antivirus vendor with its own product interest.
Recommendations
- Disable remote access to router management from the internet.
- Replace routers for which the manufacturer no longer provides security updates.
Links to the original source and the Web Archive open in a new tab.