Researchers from Top10VPN report to Cyber Security News that they have uncovered major vulnerabilities in tunneling protocols that allow attackers to hijack millions of internet hosts, including VPN servers and private home routers.
Researchers have disclosed critical vulnerabilities in widely-used internet tunneling protocols, leaving over 4.2 million hosts at risk of exploitation.
Also highlights the alarming extent to which attackers can hijack internet hosts to conduct anonymous attacks, perform denial-of-service (DoS) campaigns, and gain unauthorized access to private networks.
Key Attacks Identified:
Investigate Real-World Malicious Links & Phishing Attacks With ANY.RUN Malware Sandbox - Try for Free
The vulnerabilities stem from the fact that certain tunneling protocols fail to authenticate the origin of incoming packets. This flaw allows adversaries to exploit hosts as “one-way proxies” for launching attacks or accessing private networks. The affected protocols include:
Over 4.26 million vulnerable hosts have been identified, spanning a wide range of devices, including VPN servers, ISP home routers, CDN nodes, mobile network gateways, and core internet routers.
Here’s the data in a table format:
| Tunneling Protocol | Vulnerable Hosts | Spoofing Capable |
|---|---|---|
| IPIP | 530,100 | 66,288 |
| IP6IP6 | 217,641 | 333 |
| GRE | 1,548,251 | 219,213 |
| GRE6 | 1,806 | 360 |
| 4in6 | 130,217 | 4,113 |
| 6in4 | 2,126,018 | 1,650,846 |
The global impact is significant, with China, France, the United States, Japan, and Brazil being among the most affected countries.
Additionally, more than 11,000 Autonomous Systems (ASs) were found to be vulnerable, including major networks such as China Mobile, Softbank, and Telmex.
Top10VPN informed Cybersecurity News that “the identified vulnerabilities could allow attackers to exploit systems in various ways, including launching anonymous attacks via unauthenticated packet forwarding and IP spoofing.”
They can also execute advanced denial-of-service (DoS) techniques, such as Ping-Pong Amplification and Routing Loop Attacks.
Additionally, these weaknesses enable the spoofing of DNS queries, manipulation of network traffic, and unauthorized access to private networks via hijacked devices.
Two novel denial-of-service (DoS) attack methods, Tunneled-Temporal Lensing (TuTL) and Economic Denial of Sustainability (EDoS), exploit specific vulnerabilities in networks and devices.
TuTL strategically floods traffic during narrow time windows, overwhelming the victim’s resources, while EDoS amplifies data traffic to increase operational costs, particularly for cloud-hosted services.
These attacks target a wide array of devices, including consumer and enterprise VPN servers, home routers (notably those linked to French ISP Free, affecting over 726,000 devices), and critical enterprise infrastructure reliant on GRE/GRE6 protocols.
A global analysis reveals vulnerabilities across 218 countries, with China and France hosting the majority of spoofing-capable hosts.
Additionally, two autonomous systems are responsible for nearly half of the identified weaknesses, highlighting the systemic nature of the risk.
Professors Vanhoef and Beitis conducted a comprehensive scan of the IPv4 and IPv6 address spaces, identifying 4.26 million vulnerable hosts across multiple tunneling protocols, with 1.86 million capable of IP spoofing.
These vulnerabilities span critical networking protocols, including IPIP/IP6IP6, GRE/GRE6, and 6in4/4in6, commonly used for routing, VPN connections, and facilitating IPv6 and IPv4 interoperability.
The findings highlight significant security gaps, particularly in devices exposed to the internet.
The IPIP and IP6IP6 protocols, affecting 747,741 hosts, are commonly used in Linux-based networking and VPN setups but lack authentication and encryption mechanisms.
Many of the vulnerable systems, primarily servers with open HTTP/HTTPS ports, were linked to domains such as Facebook’s CDN and Tencent’s cloud services.
These protocols often encapsulate IPsec traffic but expose endpoints due to their inherent insecurity.
GRE and GRE6 protocols, with over 1.55 million vulnerable hosts, were widely exploited in enterprise and mobile networks.
These protocols add minimal security layers and were used on core internet routers, including those managing BGP and GTP traffic.
Major domains affected included ISPs and telecom operators, pointing to risks in critical infrastructure.
The 6in4 and 4in6 protocols accounted for nearly half of all vulnerabilities, affecting over 2.25 million hosts.
These tunneling methods enable IPv6 traffic over IPv4 networks and vice versa, underscoring the challenges of slow IPv6 adoption.
Most affected devices were ISP-provided routers with open NTP and SNMP ports, tied to ISPs in countries like France, India, and Japan.
Most Affected ISPs:
Security experts have proposed defense strategies at both the host and network levels:
This study builds on earlier work by researcher Livneh Yannay, who discovered similar flaws in IPv4 tunneling protocols in 2020. The latest findings expand the scope, exploring vulnerabilities in IPv6, additional tunneling protocols, and their security implications.
Working with CERT/CC, Professor Vanhoef and his team have alerted affected parties worldwide, prompting companies and ISPs to secure their networks.
Integrating Application Security into Your CI/CD Workflows Using Jenkins & Jira -> Free Webinar
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…