Critical OpenWrt Vulnerability Exposes Devices to Malicious Firmware Injection

Post Reply
Shane1145
Posts: 1689
Joined: Wed Sep 25, 2024 2:31 pm

Critical OpenWrt Vulnerability Exposes Devices to Malicious Firmware Injection

Post by Shane1145 »

A security flaw has been disclosed in OpenWrt's Attended Sysupgrade (ASU) feature that, if successfully exploited, could have been abused to distribute malicious firmware packages.

The vulnerability, tracked as CVE-2024-54143, carries a CVSS score of 9.3 out of a maximum of 10, indicating critical severity. Flatt Security researcher RyotaK has been credited with discovering and reporting the flaw on December 4, 2024. The issue has been patched in ASU version 920c8a1.


https://thehackernews.com/2024/12/criti ... poses.html
Post Reply