[ISN] Huawei looking into critical router flaw claims

From: InfoSec News <alerts_at_private>
Date: Fri, 3 Aug 2012 03:08:41 -0500 (CDT)
http://www.theregister.co.uk/2012/08/02/huawei_90s_router_vulnerabilities/

By Phil Muncaster
The Register
2nd August 2012

Chinese telecoms kit maker Huawei has said it is investigating claims by 
researchers that two of its router products contain serious 
vulnerabilities which could allow hackers to remotely take control of 
the devices.

Felix Lindner and Gregor Kopf of Berlin-based Recurity Labs announced 
their findings at the Defcon hacking show at the weekend (via The H), 
claiming that the products contain 1990s-style code and no operating 
system hardening, leaving them vulnerable to “90s style exploitation”.

The major coding error pointed out by the duo was a heap overflow 
vulnerability in the software of the AR18 and AR28 products, which are 
designed for use by home office workers and mid-sized enterprises 
respectively.

Huawei also produces routers and other kit for big-name global telecoms 
clients, although the researchers claimed they did not have access to 
test these high end products.

Lindner and Kopf complained that it has been virtually impossible to 
responsibly disclose their findings to Huawei because there is no 
obvious “externally visible product security group” and because the firm 
doesn’t publish security advisories for any products.

[...]


--
Learn how to be a Pen Tester, CISSP, ISSMP, or ISSAP with Expanding Security online.
Come to a free class and see how good and fun the program really is.
http://www.expandingsecurity.com/PainPill
Received on Fri Aug 03 2012 - 01:08:41 PDT

This archive was generated by hypermail 2.2.0 : Fri Aug 03 2012 - 01:15:54 PDT