Critical Vulnerability Exposes Millions of Routers to Cyber Threats
Recent developments have revealed that more than 12 million home and business routers worldwide are at risk due to a significant software vulnerability, enabling potential exploitation by malicious hackers. This critical flaw allows attackers to remotely monitor user traffic and gain administrative control over the devices, affecting a wide range of manufacturers.
The vulnerability stems from the web server “RomPager,” developed by AllegroSoft, which is integrated into the firmware of routers, modems, and other gateway devices from many leading brands. This HTTP server provides users with a convenient web interface for configuring their networking equipment. Unfortunately, versions of RomPager predating 4.34—dating back over a decade—are susceptible to a flaw identified as “Misfortune Cookie.”
Security researchers from Check Point found that this vulnerability can be exploited through a specifically crafted HTTP request targeting the RomPager server. By manipulating cookies, attackers can compromise the device’s memory, thus gaining administrative access. Once this access is achieved, they can execute a variety of malicious actions, including monitoring internet activity, intercepting unencrypted data, altering DNS settings, and even controlling other devices connected to the network.
Misfortune Cookie is officially tracked as CVE-2014-9222 in the Common Vulnerabilities and Exposures database. According to Check Point’s malware and vulnerability research manager, Shahar Tal, attackers can manipulate the HTTP sessions to impose administrative privileges on their malicious activities, posing a considerable risk to device owners.
The vulnerability affects a wide spectrum of gateway devices and small office/home office (SOHO) routers from numerous manufacturers, including prominent brands such as D-Link, Edimax, Huawei, TP-Link, ZTE, and ZyXEL. Moreover, the ramifications extend beyond routers and modems; any device connected to these vulnerable routers—such as PCs, smartphones, tablets, and smart home gadgets—could also be at risk if the router itself is compromised.
Alarmingly, the Misfortune Cookie flaw can be exploited from anywhere in the world, even if the vulnerable gateway devices do not expose their web-based administration interfaces to the internet. This is due to the common practice of leaving routers configured to accept connection requests on port 7547 as part of a remote management protocol known as TR-069 (Customer Premises Equipment WAN Management Protocol). Therefore, attackers can send a malicious cookie to this port, effectively targeting the vulnerable server software.
The origins of this vulnerability date back to 2002, with AllegroSoft reportedly addressing the issue in its RomPager software by 2005. However, many current devices from leading manufacturers still utilize affected versions of RomPager. Check Point’s assessment indicates the staggering presence of these vulnerable devices in homes and businesses, underscoring the ongoing risk of exploitation.
The critical nature of the Misfortune Cookie vulnerability was emphasized by Tal, who highlighted that if left unaddressed, it could grant hackers not only access to sensitive personal data but also control over smart home systems. While Check Point has yet to detect any active attacks leveraging this vulnerability, the company remains vigilant in monitoring for potential exploitation of older, unresolved vulnerabilities in routers and gateway devices.
In summary, business owners must be aware of the substantial risks posed by this widespread vulnerability and take proactive measures to secure their networks. Understanding the potential for initial access, privilege escalation, and other techniques identified in the MITRE ATT&CK framework can aid in fortifying defenses against such cyber threats. It is imperative that all network administrators review their hardware and firmware versions to ensure they are not using vulnerable systems that may expose their operations to significant security risks.