Guru3D.com
  • HOME
  • NEWS
    • Channels
    • Archive
  • DOWNLOADS
    • New Downloads
    • Categories
    • Archive
  • GAME REVIEWS
  • ARTICLES
    • Rig of the Month
    • Join ROTM
    • PC Buyers Guide
    • Guru3D VGA Charts
    • Editorials
    • Dated content
  • HARDWARE REVIEWS
    • Videocards
    • Processors
    • Audio
    • Motherboards
    • Memory and Flash
    • SSD Storage
    • Chassis
    • Media Players
    • Power Supply
    • Laptop and Mobile
    • Smartphone
    • Networking
    • Keyboard Mouse
    • Cooling
    • Search articles
    • Knowledgebase
    • More Categories
  • FORUMS
  • NEWSLETTER
  • CONTACT

New Reviews
Corsair H170i Elite Capellix XT review
Forspoken: PC performance graphics benchmarks
ASRock Z790 Taichi review
The Callisto Protocol: PC graphics benchmarks
G.Skill TridentZ 5 RGB 6800 MHz CL34 DDR5 review
Be Quiet! Dark Power 13 - 1000W PSU Review
Palit GeForce RTX 4080 GamingPRO OC review
Core i9 13900K DDR5 7200 MHz (+memory scaling) review
Seasonic Prime Titanium TX-1300 (1300W PSU) review
F1 2022: PC graphics performance benchmark review

New Downloads
FurMark Download v1.33.0.0
Intel ARC graphics Driver Download Version: 31.0.101.4091
Corsair Utility Engine Download (iCUE) Download v4.33.138
CPU-Z download v2.04
AMD Radeon Software Adrenalin 23.1.2 (RX 7900) download
GeForce 528.24 WHQL driver download
Display Driver Uninstaller Download version 18.0.6.0
Download Intel network driver package 27.8
ReShade download v5.6.0
Media Player Classic - Home Cinema v2.0.0 Download


New Forum Topics
RTX 4090 Owner's thread NVIDIA GeForce 528.24 WHQL driver download & Discussion AMD Ryzen 7 7700X sees price drop to $299 Netflix threatens to ban customers who share an account unauthorized GeForce NVIDIA RTX 6000 with fully active AD102  Does Not Beat RTX 4090  in 3DMark AMD Software: Adrenalin Edition 23.1.2 for AMD Radeon™ RX 7900 Series Ambient Occlusion doesn't work on my laptop Review: ASRock Z790 Taichi motherboard Grab for free: Dishonored: Death of the Outider at Epic Games Store CORSAIR introduces the new VENGEANCE a8100 and i8100 gaming PCs




Guru3D.com » News » Millions Linksys and Netgear other routers and IoT devices are vulnerable to DNS poisoning

Millions Linksys and Netgear other routers and IoT devices are vulnerable to DNS poisoning

by Hilbert Hagedoorn on: 05/05/2022 08:34 AM | source: Bleeping Computer | 10 comment(s)
Millions Linksys and Netgear other routers and IoT devices are vulnerable to DNS poisoning

An unresolved DNS vulnerability affects millions of Linksys and Netgear routers, as well as other IoT equipment. Nozomi Networks Labs security researchers found CVE-2022-05-02, a DNS implementation flaw in two prominent C libraries. uClibc and uClibc-ng are commonly found in routers and IoT devices.

DNS poisoning is essentially fooling the target device into pointing to an arbitrarily defined endpoint and communicating with it over the network. The attacker would then be able to divert traffic to a server under their direct control. A threat actor can employ DNS poisoning or DNS spoofing to send the victim to a malicious website hosted at an IP address on the attacker's server rather than the genuine destination. The OpenWRT team's fork, uClibc-ng, and the library uClibc. Both types are extensively utilized by major companies like as Netgear, Axis, and Linksys, as well as embedded Linux releases. According to Nozomi Networks experts, a remedy from the uClibc developer is not yet available, putting products from up to 200 companies at risk.

  • "Because this vulnerability remains unpatched, for the safety of the community, we cannot disclose the specific devices we tested on," says Nozomi
  • "We can, however, disclose that they were a range of well-known IoT devices running the latest firmware versions with a high chance of them being deployed throughout all critical infrastructure."

Users of IoT and router devices should keep a lookout for new firmware releases from suppliers and install the most recent upgrades as soon as they are available.



Millions Linksys and Netgear other routers and IoT devices are vulnerable to DNS poisoning




« Qualcomm Introduces Wi-Fi 7 Networking Pro Series - Up to 33.1 Gbps · Millions Linksys and Netgear other routers and IoT devices are vulnerable to DNS poisoning · Advertisement: May sale: Windows 10 lifetime license only $12 »

Related Stories

Intel Determined to bring gamers millions of Intel ARC GPUs each year - 01/31/2022 10:27 AM
When it comes to GPUs, the situation has reached rock bottom, with interesting GPUs selling out instantly or at exorbitant prices, and brands releasing products that would never have existed in a norm...

Facebook stored millions of passwords unencrypted - 03/22/2019 09:57 AM
The credit for c***up of the year goes to Facebook. The company keeps promising things but as it now turns out it stored the passwords of hundreds of millions of users completely unencrypted, yes that...

DRAM makers likely to get fined millions (if not billions) on antitrust fines in China - 06/21/2018 04:39 PM
The Chinese authorities have been investigating the DRAM market for a while now. We've reported on this topic several already. From the looks of it, things are about the get worse for the big three M...

Millions Of Routers Vulnerable To Attacks Due To NetUSB Bug - 05/25/2015 08:46 AM
A serious vulnerability affecting the NetUSB kernel driver developed by Taiwan-based tech company KCodes exposes millions of routers to hack attacks, researchers have warned. According to its website,...

Millions of infected machines might go offline March 8 - - 02/18/2012 02:02 PM
In three weeks, the FBI could knock millions of infected systems offline by disabling some DNS servers as techspot reported. In November, Estonian authorities arrested six men suspected of using &quot...


2 pages 1 2


TheDeeGee
Senior Member



Posts: 8489
Joined: 2010-08-28

#6014706 Posted on: 05/05/2022 09:41 AM
Still using a Netgear R7000 Nighthawk, it's running Xwrt-Vortex.

anticupidon
Senior Member



Posts: 7062
Joined: 2008-03-06

#6014707 Posted on: 05/05/2022 09:59 AM
The S in the IoT stands for security.

Sarcasm aside, hope that a patch will be released soon.

Sylwester Zarębski
Member



Posts: 32
Joined: 2020-03-23

#6014834 Posted on: 05/05/2022 07:08 PM
OpenWRT is not using uClibc/uClibc-ng since 2015: https://forum.openwrt.org/t/nozomi-dns-poisoning-bug-affects-openwrt/126768

Mufflore
Senior Member



Posts: 13853
Joined: 2010-05-22

#6015274 Posted on: 05/07/2022 04:04 AM
I manually configure DNS on my network adapters.
Only needs to be done once.

Venix
Senior Member



Posts: 2866
Joined: 2016-08-01

#6015633 Posted on: 05/09/2022 07:29 AM
I manually configure DNS on my network adapters.
Only needs to be done once.

Yeah on everything my self I have DNS set up to 1.1.1.1 !

2 pages 1 2


Post New Comment
Click here to post a comment for this news story on the message forum.


Guru3D.com © 2023