News

Severe UPnP Flaw Allows Router Hijacking

Thomas Claburn
Editor-at-Large

Security researchers warn that 99% of home routers are vulnerable to this attack.

A vulnerability in networking devices that support UPnP (Universal Plug and Play) can be exploited through a malicious SWF (Flash) file on a Web site, US-CERT warned Monday.

Visiting such a Web site may allow an attacker to reconfigure or take over devices connected to the victim's system that support UPnP. This includes routers, cameras, printers, mobile phones, and digital entertainment systems.


More Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

The attack has been explored in more detail on GNUCitizen.org, a security consultancy.

Petko D. Petkov, the group's founder, describes the UPnP/Flash vulnerability as "highly severe." Successfully executing the attack allows the attacker to take over the affected router, allowing him or her to bypass firewalls, access Web router administration pages, attack Internet hosts through the router, and alter networking settings.

"The most malicious of all malicious things is to change the primary DNS server," Petkov explains. "That will effectively turn the router and the network it controls into a zombie which the attacker can take advantage of [at will]. It is also possible to reset the admin credentials and create the sort of onion routing network all the bad guys want."

Petkov warns that 99% of home routers are vulnerable to this attack. Along with US-CERT, he warns that anyone with UPnP devices turn off the UPnP protocol (consult your router manual). UPnP is typically turned on by default and contains no form of authentication to prevent this attack, according to Petkov.

Disabling Adobe's Flash software may not be effective, Petkov cautions, because other Web technologies may also provide a means to exploit the UPnP flaw.

Related Reading


Informationweek Discussions

Start the Discussion


InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS

Resource Links