bk99.de entertain the web since 1997

TP-Link: smuggling malicious code through a security hole in routers

Summary

In 2022 researchers from the Vietnamese telecommunications group Viettel found a buffer overflow in the web-based ping tool of the low-cost TP-Link TL-WR841N Wi-Fi router (CVE-2022-30024). Logged-in attackers could execute their own code via an overlong host address and, for example, install a backdoor. TP-Link delivered updates for revisions V10 to V12 and declared older devices end-of-life.

Ideas

  • Diagnostic tools in the web interface are a common entry point for code execution.
  • Overlong input overflows the firmware’s internal buffers.
  • The required login lowers the risk but does not prevent botnet combinations.
  • Older hardware revisions of the same model received no fix.

Insights

  • With routers, the same model name says little about support status; the revision is what matters.
  • Cheap mass-market routers are attractive botnet building blocks because they are so widespread.

Facts

  • The hole has a CVSS score of 8.8.
  • Fixed firmware appeared as V10_200325, V11_211209 and V12_220802.

References

Critique

  • The report does not say whether default passwords make the required login trivial in practice.

Recommendations

  • Check the hardware revision on the type plate before searching for firmware updates.
  • Replace routers whose revision no longer receives security updates, or install OpenWrt.

Read the original article

Search the Web Archive