Bugs Batter Linksys Routers Opening Them Up To Becoming Botnets

Security flaws in Linksys routers have been discovered by researchers, who found that vulnerable Wi-Fi routers could be exploited and turned into botnets.

Researcher Tao Sauvage from cyber security firm IOActive Group and independent researcher Antide Petit, uncovered ten separate vulnerabilities in more than 20 Linksys Smart Wi-Fi routers, and identified  some 7,000 devices susceptible to exploitation.

Linksys security holes

The security flaws, if exploited, could be used to overload a targeted router and force it to reboot, as well as deny a legitimate user access to it, leak sensitive information about the router and devices connected to it, and change restricted settings.

“A number of the security flaws we found are associated with authentication, data sanitisation, privilege escalation, and information disclosure,” said Sauvage.

“Additionally, 11 percent of the active devices exposed were using default credentials, making them particularly susceptible to an attacker easily authenticating and potentially turning the routers into bots, similar to what happened in last year’s Mirai Denial of Service (DoS) attacks.”

IOActive informed Linksys of the vulnerabilities in January, and both companies have been working together to plug the security holes.

Currently, Linksys and IOActive have come up with a workaround to avoid the risks posed by the vulnerabilities, until Linksys pushes out a firmware patch in the coming weeks.

Linksys’s advisory advises users to enable automatic updates on their router, disable the Wi-Fi guest network if it’s not being used, and naturally change the default administrators password.

With the potential to turn Wi-Fi routers into botnets and wreak havoc in a similar vein to the Mirai botnet, such flaws are deeply problematic, particularity when the distribution of routers from established brands is worldwide.

Are you a security pro? Try our quiz!

Roland Moore-Colyer

As News Editor of Silicon UK, Roland keeps a keen eye on the daily tech news coverage for the site, while also focusing on stories around cyber security, public sector IT, innovation, AI, and gadgets.

Recent Posts

Brazil Unfreezes Starlink, X Bank Accounts After Funds Transfer

Judge orders X, Starlink bank accounts unfrozen after $3.3m transfer pays off fines imposed on…

17 hours ago

Uber To Offer Waymo Robotaxi Rides In Austin, Atlanta

Uber expands deal with Waymo from Phoenix to Austin, Texas and Atlanta as it faces…

17 hours ago

GenAI Shopping: Revolutionising Retail Experiences

Discover how Generative AI is transforming the retail experience with personalised interactions, AI-powered search, and…

18 hours ago

US House Passes Bill Targeting Chinese EV Battery Tech

US House of Representatives passes bill restricting tax credits for electric vehicles using battery technology…

18 hours ago

NASA Mission To Jupiter’s Europa Gets Go-Ahead

NASA to launch 'Europa Clipper' mission to Jupiter's moon Europa next month as it seeks…

18 hours ago

Police Arrest Youth Over London Transport Hack

National Crime Agency arrests 17-year-old in Walsall over hack of Transport for London that compromised…

19 hours ago