All Stories
Follow
Subscribe to ONEKEY GmbH

ONEKEY GmbH

Hackers welcome: Major security test uncovers vulnerabilities in all common Wi-Fi routers

Hackers welcome: Major security test uncovers vulnerabilities in all common Wi-Fi routers

  • IoT Inspector and CHIP examine devices from AVM, Asus, Netgear, and more
  • New German coalition announces manufacturer liability for damages caused by IT security vulnerabilities

Bad Homburg/Germany, December 2, 2021 - Nine Wi-Fi routers from well-known manufacturers recently underwent a thorough security test under laboratory conditions - with devastating results in the field of IT security: A total of 226 potential security vulnerabilities were found in the devices from Asus, AVM, D-Link, Netgear, Edimax, TP Link, Synology and Linksys, which are in circulation by the millions. The front-runners were devices from TP-Link with 32 vulnerabilities (TP-Link Archer AX6000) and Synology with 30 vulnerabilities (Synology RT-2600ac). The test was conducted by the editors of the German IT magazine CHIP together with the experts from IoT Inspector, who provided their security platform for automated IoT firmware checks for this purpose. "The test negatively exceeded all expectations for secure small business and home routers. Not all vulnerabilities are equally critical - but at the time of the test, all devices showed significant security vulnerabilities that could make a hacker’s life much easier" says Florian Lukavsky, CTO of IoT Inspector.

Manufacturers have responded - so have policymakers

All of the affected manufacturers were contacted by the test team and given the opportunity to respond. Without exception, all responded with more or less intensively prepared firmware patches, which users of the affected routers should now urgently apply, in case the automatic update function is not already activated. “Following our test, the affected manufacturers have already patched a lot of security gaps in their devices. But Wi-Fi routers are still not flawless. Manufacturers still have some catching up to do," says CHIP author Jörg Geiger. At the same time, the coalition agreement of the new German government announces that manufacturers will be required to take greater accountability in the future. It states that "manufacturers are liable for damage negligently caused by IT security vulnerabilities in their products." This increases the pressure on the industry to continuously secure products in order to avoid immense claims for damages. IoT Inspector's firmware security checks automate this important step of analysis. All it takes is to upload a device's firmware to iot-inspector.com. Within minutes, the platform generates a detailed report and risk rating of the detected vulnerabilities, which can then be addressed in a targeted manner.

Typical problems with all manufacturers

Some of the security issues were detected more than once. Very frequently, an outdated operating system, i.e. Linux kernel, is in use. Since the integration of a new kernel into the firmware is costly, no manufacturer was up to date here. The device software used is also commonly found to be outdated, as it all too often relies on standard tools like BusyBox. Additional services that the devices offer besides routing - such as multimedia functions or VPN - tend to be outdated as well. In fact, a large number of manufacturers use default passwords like "admin", which in many cases can be read in plain text. "Changing passwords on first use and enabling the automatic update function must be standard practice on all IoT devices, whether the device is used at home or in a corporate network. The greatest danger, besides vulnerabilities introduced by manufacturers, is using an IoT device according to the motto 'plug, play and forget'," warns IoT Inspector’s CEO Jan Wendenburg.

About IoT Inspector:

IoT Inspector is the leading European platform for IoT security analysis and enables automated firmware testing of IoT devices for critical security vulnerabilities in just a few clicks. The integrated Compliance Checker simultaneously uncovers violations of international compliance requirements. Vulnerabilities for external attacks and security risks are identified in the shortest possible time and can be remedied in a targeted manner. The solution, which is easy to use via the web interface, detects unknown security risks for manufacturers and distributors of IoT technology. This is especially true for products manufactured by an OEM partner. Infrastructure providers, consulting companies, scientists and system houses also benefit from the offering and can provide added value to their customers.

Company Contact: IoT Inspector GmbH,
Tannenwaldallee 2, 61348 Bad Homburg, Germany,
Julia Alunovic, E-Mail:  julia@iot-inspector.com,
Web:  https://www.iot-inspector.com
 
PR Agency: euromarcom public relations GmbH,
Mühlhohle 2, 65205 Wiesbaden, Germany,
Tel.: +49 611 9731 50, E-Mail:  team@euromarcom.de,
Web:  www.euromarcom.de

- - - -

More stories: ONEKEY GmbH
More stories: ONEKEY GmbH
  • 09.11.2021 – 15:35

    Extended EU RED Directive enforces higher IoT security by 2024

    Extended EU RED directive enforces higher IoT security by 2024 80 percent of cyberattacks are directed against wireless devices Bad Homburg/Germany, November 9th, 2021 – The Internet of Things, i.e. especially all wireless smart devices, poses one of the greatest risks in information technology. By introducing new security requirements, the EU Commission is now significantly raising the bar for manufacturers and ...

  • 28.10.2021 – 11:45

    Protection against critical security gaps in telecommunication networks

    Protection against critical security gaps in telecommunication networks IoT Inspector saves Swisscom €350,000 per avoided faulty software rollout and update Bad Homburg/Germany, October 28th 2021 – With a turnover of over 10 billion euros and almost 20,000 employees, Switzerland’s technology and telecommunications company Swisscom is the industry leader in its ...