ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Consumer routers targeted by DNS hijacking attackers

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-1652
Authenticated Command Injection in Cisco RV320/RV3325 Small Business Routers

CVE-2019-1652 is an improper input validation flaw (CWE-20, leading to command injection per CWE-78) in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN routers. An authenticated, remote attacker who already holds administrative privileges on the device exploits it by sending crafted HTTP POST requests to the management interface, and a successful exploit allows arbitrary command execution as root on the underlying Linux shell. Because administrative credentials are required, the bug is typically a second stage of an attack on an internet-facing edge router rather than a standalone entry point. All RV320 and RV325 routers running firmware predating the firmware updates Cisco released are affected, and these models have since reached end-of-life. Exploitation is confirmed in the wild: the vulnerability was added to CISA's KEV catalog on 2022-03-03, carries a 95.9% EPSS probability (100th percentile), has had public PoCs since 2019, and news coverage reports attackers — including China-linked groups — targeting the roughly 9,000 RV320/RV325 units exposed online.

Do: Apply the firmware updates Cisco released for the RV320/RV325 per the vendor advisory, as required by the CISA KEV listing, and since these routers are end-of-life, plan hardware replacement where the updated firmware cannot be installed. In the interim, restrict access to the web-based management interface to trusted networks only and check exposed devices for signs of compromise, given active targeting by China-linked threat actors.

7.296% KEV PoC ×5
  • Cisco Small Business RV320 Dual Gigabit WAN VPN Router (firmware)
  • Cisco Small Business RV325 Dual Gigabit WAN VPN Router (firmware)
moderate≈9,000+ internet-exposed RV320/RV325 routers per public scans; total deployed base unknown but larger
CVE-2019-1653
Unauthenticated Config Disclosure in Cisco RV320/RV325 Routers

CVE-2019-1653 is an improper access control flaw (CWE-284) in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN routers. It is triggered by sending requests to vulnerable URLs on the management interface without authentication, bypassing the intended access controls. An attacker gains the ability to download the full router configuration — which can expose credentials and VPN/VPN-tunnel settings — as well as detailed diagnostic information about the device. Any Cisco RV320 or RV325 router whose management interface is reachable, particularly over the internet, is affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) and carries a 99.9% EPSS score, though no public proof-of-concept is known and no ransomware association has been confirmed.

Do: Apply the updated router firmware from Cisco as instructed in the vendor advisory, per the CISA KEV required action. If updating is not immediately possible, restrict or disable WAN-side access to the web management interface and limit it to trusted management hosts. Because the downloaded configuration can contain credentials, change administrative and VPN passwords after patching, and review logs for signs of unauthenticated configuration downloads.

7.5100% KEV PoC ×5
  • Cisco Small Business RV320 Dual Gigabit WAN VPN Router
  • Cisco Small Business RV325 Dual Gigabit WAN VPN Router
largetens of thousands of internet-exposed routers (public internet-wide scans at disclosure found on the order of 20,000–30,000 RV320/RV325 devices with reachable…
CVE-2019-1828
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remot

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to access administrative credentials. The vulnerability exists because affected devices use weak encryption algorithms for user credentials. An attacker could exploit this vulnerability by conducting a man-in-the-middle attack and decrypting intercepted credentials. A successful exploit could allow the attacker to gain access to an affected device with administrator privileges. This vulnerability affects Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers running firmware releases prior to 1.4.2.22.

NVD description · AI analysis pending
8.1<1%
  • cisco rv320 firmware
  • cisco rv325 firmware
Full article574 words · extracted from helpnetsecurity.com · click to collapse

Owners of a slew of D-Link, ARGtek, DSLink, Secutech, TOTOLINK and Cisco consumer routers are urged to update their device’s firmware, lest they fall prey to ongoing DNS hijacking campaigns and device hijacking attacks.

consumer routers DNS hijacking

Targeted Cisco routers

The Cisco routers targeted are Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN routers.

The exploited vulnerabilities are CVE-2019-1653, CVE-2019-1652, and CVE-2019-1828.

All three are in the web-based management interface of the routers and could allow an unauthenticated, remote attacker to retrieve sensitive information, execute arbitrary commands, or access administrative credentials.

The first two have been patched unsuccessfully in the past, but Cisco has now pushed out a firmware update (v1.4.2.22) that supposedly fixes them for good.

The same security update also plugs CVE-2019-1828, a vulnerability that exists because affected devices use weak encryption algorithms for user credentials.

“An attacker could exploit this vulnerability by conducting a man-in-the-middle attack and decrypting intercepted credentials. A successful exploit could allow the attacker to gain access to an affected device with administrator privileges,” Cisco explained, and noted that its Product Security Incident Response Team (PSIRT) “is aware of the public announcement or malicious use of the vulnerability.”

The DNS hijacking campaign

The on-and-off DNS hijacking campaign has been documented by security researcher Troy Mursch of Bad Packets Report.

The campaign was effected in three bursts: the first one in December 2018, the second in February 2019 and the third in March 2019.

Throughout the various campaigns, the targeted (vulnerable) routers were:

  • D-Link DSL-2640B
  • D-Link DSL-2740R
  • D-Link DSL-2780B
  • D-Link DSL-526B
  • ARG-W4 ADSL
  • DSLink 260E
  • Secutech routers and TOTOLINK routers.

“All exploit attempts have originated from hosts on the network of Google Cloud Platform,” Mursch noted.

“Google makes it very easy for a miscreants to abuse their platform. Anyone with a Google account can access a ‘Google Cloud Shell’ machine by simply visiting this URL. This service provides users with the equivalent of a Linux VPS with root privileges directly in a web browser. Due to the ephemeral nature of these virtual machines coupled with Google’s slow response time to abuse reports, it’s difficult to prevent this kind of malicious behavior.”

The attackers’ goal was to change the target routers’ DNS settings to point to various rogue DNS servers, so that users may be redirected to malicious IPs (e.g., fake bank websites).

“In all three waves, a recon scan was done using Masscan to check for active hosts on port 81/tcp prior to attempting the DNS hijacking exploits,” Mursch added.

Owners of targeted routers are advised to check whether their router’s DNS settings have been tampered with (the rogue DNS servers used in this campaign are/were located at 66.70.173.48, 144.217.191.145, 195.128.126.165 and 195.128.124.131) and, if they have, to change them to one of the legitimate, public DNS resolvers.

Those who haven’t been affected should make sure to have the latest firmware available installed.

UPDATE (April 6, 2019, 08:25 a.m. PT):

“We have suspended the fraudulent accounts in question and are working through established protocols to identify any new ones that emerge,” a Google Cloud spokesperson told Help Net Security.

“We have processes in place to detect and remove accounts that violate our terms of service and acceptable use policy, and we take action on accounts when we detect abuse, including suspending the accounts in question. These incidents highlight the importance of practicing good security hygiene, including patching router firmware once a fix becomes available.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2019/04/05/consumer-routers-dns-hijacking/