12
DSL router hijacking vulnerability found
A susceptibility in the ZynOS firmware of Zyxeltech, which is used in DSL routers that are numerous worldwide, is exposing a lot of the apparatus to a DNS hijacking assault.
An associate of the Bulgarian security research group Ethical Hacker, Todor Donev, shown the vulnerability that allows hackers to modify the DNS settings on routers.
Endangered routers will enable hackers to redirect a user’s traffic to malicious websites, and steal private information.A user obtaining a banking website, as an example, could be redirected to a phishing website that’ll collect sensitive information.
Other assaults may contain shoving malware to users, and replacing advertisements on websites that are valid.
As stated by The Stack, the strike will “operate most readily on affected routers that are configured for remote management, but can be executed via Cross-Site Request Forgery (CSRF)”.
A number of the routers changed contain D-Link’s DSL-2740R ADSL router, along with DSL routers from TPLink and ZTE.
There are no comments.