A critical zero-day vulnerability has been discovered in TP-Link Archer, Deco, and Tapo series routers, potentially allowing attackers to inject malicious commands and fully compromise affected devices.
This vulnerability, present in both old and recent firmware versions up to November 4th, 2024, highlights significant security concerns for users of these popular router models.
The vulnerability was initially identified in an old firmware version of the AXE75 router from 2023, but further investigation revealed its presence in the most recent firmware release.
Security researchers employed various techniques to analyze and exploit this vulnerability:-
The critical flaw was discovered in the avira.lua file, ironically part of the Avira antivirus software intended to protect the device.
ThottySploity researchers identified that the vulnerability lies in the “tmp_get_sites” function, where the ownerId variable is passed to the os.execute function without proper sanitization or validation.
Leveraging 2024 MITRE ATT&CK Results for SME & MSP Cybersecurity Leaders – Attend Free Webinar
Researchers developed an exploit that targets the vulnerability through the “/admin/smart_network” endpoint.
By manipulating the ownerId parameter, attackers can inject malicious commands and execute them with root privileges on the affected routers. This allows for actions such as dumping sensitive files like “/etc/ passwd” and “/etc/ shadow.”
The vulnerability was responsibly disclosed to TP-Link following its discovery on October 3, 2024. Key events in the disclosure timeline include:
To mitigate this vulnerability, TP-Link should implement proper input sanitization for the ownerId variable, such as using the tonumber function in Lua to prevent text injection.
This discovery underscores the importance of continuous security auditing and responsible disclosure in the realm of network device firmware.
Users of affected TP-Link routers are advised to update their firmware as soon as patches become available to protect against potential exploitation of this vulnerability.
Analyse Advanced Malware & Phishing Analysis With ANY.RUN Black Friday Deals : Get up to 3 Free Licenses.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…