Tag: Firmware Injection

Critical OpenWrt Vulnerability Exposes Devices to Malicious Firmware Injection
News

Critical OpenWrt Vulnerability Exposes Devices to Malicious Firmware Injection

OpenWrt's Attended Sysupgrade (ASU) feature includes a security weakness that, if successfully exploited, may have been used to spread malicious firmware packages. Tracked as CVE-2024-54143, the vulnerability has a critical severity CVSS score of 9.3 out of a possible 10. The bug was discovered and reported on December 4, 2024, by RyotaK, a researcher at Flatt Security. The ASU version 920c8a1 patch has addressed the problem. According to an alert from the project maintainers, an attacker can contaminate the legitimate image by supplying a package list that results in the hash collision because of the combination of the shortened SHA-256 hash in the build request hash and the command injection in the imagebuilder image read more about Critical OpenWrt Vulnerability Exposes Devices t...