Menu
Bayou Technologies | Lake Charles, Louisiana | Technology | Cybersecurity | Communication | Marketing
Computer IT Services & Marketing
  • Technology
    • Managed Services
    • Computer Repair
    • Consulting
  • Cybersecurity
    • BDR
    • Network Security
    • Computer Security
    • Data Recovery
  • Communication
    • Cabling
    • Wireless Networking
    • Phones
  • Marketing
    • Website Development
    • Search Engine Optimization
    • Social Media & Online Presence
    • Location Scan
    • Website & Email Management
    • Online Advertising
    • Multimedia Design
    • Newsletter
  • CALL: 337-214-1172
Widgets

HOME  |  BLOG  |  REMOTE SUPPORT

Home
Support
Blog
Contact
Close Menu
Vulnerabilities Found In Consumer Based Routers And Devices
September 30 2019

Vulnerabilities Found In Consumer Based Routers And Devices

wukovits Blog, General Interest, Recent News, Security, Technology News

The SOHOpelessly Broken 2.0 study has been released by Independent Security Evaluators .

The picture it paints of routers and the so-called ‘smart’ devices that make up the rapidly expanding Internet of Things (IoT) is not pretty.

The researchers sum up their findings as follows:

“Today, we show that security controls put in place by device manufacturers are insufficient against attacks carried out by remote adversaries.  This research project aimed to uncover and leverage new techniques to circumvent these new security controls in embedded devices.”

The research team investigated several SOHO routers and NAS devices offered by a range of manufacturers, including:

  • ASUS
  • Asustor (a subsidiary of ASUS)
  • Buffalo
  • Drobo
  • Lenovo
  • Netgear
  • QNAP
  • Seagate
  • Synology
  • TerraMaster
  • Xiaomi
  • Zioncom
  • Zyxel

Sadly, devices from every manufacturer listed above had at least one web app vulnerability that could allow a remote attacker to gain access to the administrative panel of the device in question.  Worse, the researchers reported that they were able to obtain root shells on 12 of the devices, giving them complete control. In six cases, they were able to gain complete control remotely and without authentication.

The most at-risk routers the group tested are the:

  • Asustor AS-602T
  • Buffalo TeraStation TS5600D1206
  • TerraMaster F2-420
  • Drobo 5N2
  • Netgear Nighthawk R9000
  • TOTOLINK (Zioncom) A3002RU

Since the publication of the SOHOpelessly Broken 1.0 report, the research team did say that the general state of security on IoT devices had improved somewhat. That’s a low bar given the sorry state of IoT security to begin with.  While things have no doubt improved, there are still miles to go before IoT security could be called anything approaching robust.

In fact, many of the IoT devices being sold today still lack basic web application features like browser security headers and anti-CSRF tokens.  Until these kinds of issues are addressed, the conclusions fronted by the SOHOpelessly Broken 3.0 report won’t be much better than they are now.

Used with permission from Article Aggregator

LastPass User Credentials May Have Been Exposed To Hackers New Chrome Feature Allows Sending Web Pages To Devices

Related Posts

Gen Intel Processors May Get Built In Ransomware Protection

Blog, General Interest, New Technology, Ransomware, Recent News, Security, Technology News

Gen Intel Processors May Get Built In Ransomware Protection

Firefox To Follow Chrome in Backspace Keyboard Functionality Change

Blog, Chrome, Mozilla Firefox, Recent News, Technology News

Firefox To Follow Chrome in Backspace Keyboard Functionality Change

Even Big Companies Like Nissan Get Hacked

Blog, Branding, Data Breach, General Interest, Recent News, Security, Technology News

Even Big Companies Like Nissan Get Hacked

Recent Posts

  • Gen Intel Processors May Get Built In Ransomware Protection
  • Firefox To Follow Chrome in Backspace Keyboard Functionality Change
  • Even Big Companies Like Nissan Get Hacked

Archives

Categories

Get a Domain Registered


$.99* .COM Domain! Get going with GoDaddy!

Back To Top
Bayou Technologies | Lake Charles, Louisiana | Technology | Cybersecurity | Communication | Marketing
  • Home
  • Technology
  • Cybersecurity
  • Communication
  • Marketing
  • Newsletter
  • Blog
  • Support
  • Contact

BBB Logo

Bayou Technologies, LLC
✖
Bayou Technologies is a BBB Accredited Busines
A+
On a scale of A+ to F

Reviewed, Evaluated and Accredited

Meets All 26 Standards of Accreditation

BBB Accredited since 1/1/2012

Click here for BBB Business Report on Bayou Technologies, LLC

BBB Accredited:

BBB Rating as of:

Verify Bayou Technologies, LLC
Bayou Technologies, LLC © 2019
Website Development and Marketing in Lake Charles, Louisiana
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are as essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled

Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.

Non-necessary

Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.