ZeroHour
The Recordpublished ()ingested

Routers and modems running Arcadyan firmware are under attack

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-20090
Unauthenticated Path Traversal in Arcadyan Buffalo Router Firmware

CVE-2021-20090 is a path traversal flaw (CWE-22) in the web interface of Arcadyan's Buffalo router firmware. By sending crafted HTTP requests containing directory traversal sequences, an unauthenticated, remote attacker can bypass the device's authentication. Successful exploitation grants access to sensitive information and otherwise protected functionality on the router without valid credentials. The flaw affects multiple router models across several different vendors, because Arcadyan's Buffalo firmware is embedded in a range of OEM and ISP-distributed products. Exploitation is confirmed in the wild: the vulnerability was added to CISA's KEV catalog on 2021-11-03, and EPSS rates the probability of exploitation within 30 days at 100% (100th percentile).

Do: Apply firmware updates from the router vendor as directed in the CISA KEV required action. Until patched, restrict or disable WAN-side remote management of the device's web interface. Review router configurations for unauthorized changes after patching, since unauthenticated remote access was possible.

9.8100% KEV PoC ×2
  • Arcadyan Buffalo Firmware
massplausibly millions of deployed consumer/ISP routers; internet-exposed subset unknown
CVE-2021-20091
The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly sanitize user input.

The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly sanitize user input. An authenticated remote attacker could leverage this vulnerability to alter device configuration, potentially gaining remote code execution.

NVD description · AI analysis pending
8.89%
  • buffalo wsr-2533dhpl2-bk firmware
  • buffalo wsr-2533dhp3-bk firmware

Indicators of compromiseAll →

TypeIndicatorContext
ipv41.5.0.103.00.20 Telus NH20A 1.00.10debug build06 Verizon Fios G3100 1.5.0.10 Vodafone EasyBox 904 4.16 Vodafone EasyBox 903 30.05.714 Vo
Full article603 words · extracted from therecord.media · click to collapse

Routers and modems running a version of the Arcadyan firmware, including devices from ASUS, Orange, Vodafone, and Verizon, are currently under attack from a threat actor attempting to ensnare the devices into their DDoS botnet.

First spotted by security firm Bad Packets earlier this week and confirmed by Juniper Labs on Friday, the attacks are exploiting a vulnerability tracked as CVE-2021-20090.

Discovered by Tenable security researcher Evan Grant earlier this year, the vulnerability resides in the firmware code produced by Taiwanese tech firm Arcadyan.

Grant says the vulnerability has existed in the code for at least ten years and has made its way into the firmware of at least 20 router and modem models sold by 17 different vendors, which based their products on a white-label version of old Arcadyan devices.

The list of affected devices includes some of today's biggest router vendors and internet service providers, such as ASUS, Orange, Vodafone, Telstra, Verizon, Deutsche Telekom, British Telecom, and many others.

VendorDeviceFound on version
ADBADSL wireless IAD router1.26S-R-3P
ArcadyanARV751900.96.00.96.617ES
ArcadyanVRV95176.00.17 build04
ArcadyanVGV75193.01.116
ArcadyanVRV95181.01.00 build44
ASMAXBBR-4MG / SMC7908 ADSL0.08
ASUSDSL-AC88U (Arc VRV9517)1.10.05 build502
ASUSDSL-AC87VG (Arc VRV9510)1.05.18 build305
ASUSDSL-AC31001.10.05 build503
ASUSDSL-AC68VG5.00.08 build272
BeelineSmart Box Flash1.00.13_beta4
British TelecomWE410443-SA1.02.12 build02
BuffaloWSR-2533DHPL21.02
BuffaloWSR-2533DHP31.24
BuffaloBBR-4HG
BuffaloBBR-4MG2.08 Release 0002
BuffaloWSR-3200AX4S1.1
BuffaloWSR-1166DHP21.15
BuffaloWXR-5700AX7S1.11
Deutsche TelekomSpeedport Smart 3010137.4.8.001.0
HughesNetHT2000W0.10.10
KPNExperiaBox V10A (Arcadyan VRV9517)5.00.48 build453
KPNVGV75193.01.116
O2HomeBox 64411.01.36
OrangeLiveBox Fibra (PRV3399)00.96.00.96.617ES
SkinnySmart Modem (Arcadyan VRV9517)6.00.16 build01
SparkNZSmart Modem (Arcadyan VRV9517)6.00.17 build04
Telecom (Argentina)Arcadyan VRV9518VAC23-A-OS-AM1.01.00 build44
TelMexPRV33AC1.31.005.0012
TelMexVRV7006
TelstraSmart Modem Gen 2 (LH1000)0.13.01r
TelusWiFi Hub (PRV65B444A-S-TS)v3.00.20
TelusNH20A1.00.10debug build06
VerizonFios G31001.5.0.10
VodafoneEasyBox 9044.16
VodafoneEasyBox 90330.05.714
VodafoneEasyBox 80220.02.226

Besides the wide impact, the bug wasn't initially a big deal. Found earlier this year and patched in April, the vulnerability never came under attack until this week.

Exploitation only started Thursday this week, two days after Grant published an in-depth technical write-up, which also included proof-of-concept code.

Bad Packets co-founder and CTO Troy Mursch told The Record the attacks are leveraging the proof-of-concept code shared in Grant's blog post, which is tailored to attack Buffalo routers.

As of 2021-08-05T04:09:44Z, DDoS botnet operators are scanning the internet for Buffalo routers vulnerable to CVE-2021-20091 (https://t.co/OyZT3Be2SP).

This vulnerability allows attackers to alter device configuration leading to remote code execution. #threatintel

— Bad Packets by Okta (@bad_packets) August 5, 2021

Per Grant, once exploited, the vulnerability can be used to bypass authentication procedures on affected routers and modems to enable the Telnet service and allow threat actors to connect to devices remotely.

While Grant has not tested his proof-of-concept exploit for other devices, and the exploit might not work out of the box for all, the chances are that it does.

While still unconfirmed, owners of any of the affected devices listed in the table above are advised to inquire their router vendor for security patches.

Juniper said it identified the threat actor behind these attacks as a notorious botnet herder operating a version of the Mirai malware.

No previous article

No new articles

Catalin Cimpanu

is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/routers-and-modems-running-arcadyan-firmware-are-under-attack