Germany's Fraunhofer Institute for Communication (FKIE) has carried out a study involving 127 home routers from seven brands to check for the presence of known security vulnerabilities in the latest firmware. The results are appalling.
The FKIE study found that 46 routers hadn't got a single security update within the past year and that many routers are affected by hundreds of known vulnerabilities.
It also found that vendors are shipping firmware updates without fixing known vulnerabilities, meaning that even if a consumer installs the latest firmware from a vendor, the router would still be vulnerable.
SEE:Best Wi-Fi routers for your home office in 2020: Google Wifi, ASUS ROG, and more
FKIE assessed that ASUS and Netgear do a better job on some aspects of securing routers than D-Link, Linksys, TP-Link and Zyxel, but it argues the industry needs to do more to secure home routers.
FKIE found that AVM, a German router manufacturer, was the only vendor that didn't publish private cryptographic keys in its router firmware. The Netgear R6800 router contained 13 private keys.
In the worst cases of devices FKIE assessed, the routers hadn't been updated for more than five years.
About 90% of the routers in the study used a Linux operating system. However, manufacturers weren't updating the OS with fixes made available from Linux kernel maintainers.
"Linux works continuously to close security vulnerabilities in its operating system and to develop new functionalities. Really, all the manufacturers would have to do is install the latest software, but they do not integrate it to the extent that they could and should," said Johannes vom Dorp, a scientist at FKIE's Cyber Analysis & Defense department.
"Numerous routers have passwords that are either well known or simple to crack or else they have hard-coded credentials that users cannot change," he added.
The study targeted five key signals in firmware images to assess each manufacturer's approach to cybersecurity. These included the days since the last firmware update was released; how old are the OS versions running these routers; the use of exploit mitigation techniques; whether private cryptographic key material isn't private; and the presence of hard-coded login credentials.
FKIE concludes that router makers are significantly lagging in the delivery of security updates compared with operating system makers.
"The update policy of router vendors is far behind the standards as we know it from desktop or server operating systems," FKIE notes in the report.
"Most of the devices are powered by Linux and security patches for Linux kernel and other open-source software are released several times a year. This means the vendors could distribute security patches to their devices far more often, but they do not."
The results mirror findings from a 2018 US study by American Consumer Institute (ACI), which analyzed 186 small office/home office Wi-Fi routers from 14 different vendors. It found 155, 83%, of the firmware sampled had vulnerabilities to potential cyberattacks, and that each router had an average of 172 vulnerabilities.
ACI criticized router makers for not providing an auto-update mechanism to keep routers updated. Often updates are only made after high-profile attacks on routers, such as Mirai IoT malware, and the state-sponsored VPNFilter malware.
SEE:VPN usage policy (TechRepublic Premium)
As for exploit mitigation, a researcher who recently found 79 Netgear router models had a remotely exploitable flaw also found that its web-based administration panel never applies the exploit mitigation technique ASLR (address space layout randomization), lowering the bar for remote attackers to take over an affected router.
The German study found that more than a third of the devices use a kernel version 2.6.36 or older, with the latest security update for 2.6.36 provided in February 2011. It also found a Linksys WRT54GL router running on Linux kernel version 2.4.20, which was released in 2002.
"The worst case regarding high-severity CVEs is the Linksys WRT54GL powered by the oldest kernel found in our study," the report notes. "There are 579 high-severity CVEs affecting this product."
Go here to see the original:
Home router warning: They're riddled with known flaws and run ancient, unpatched Linux - ZDNet
- Trump's Homeland Security pick pressed on domestic terrorism in hearing - NPR - January 21st, 2025 [January 21st, 2025]
- Man watches in horror from security camera as California wildfire engulfs his home: 'All I could do' - Fox Weather - January 21st, 2025 [January 21st, 2025]
- Unprecedented video shows falling meteorite, records sound of impact - For The Win - January 21st, 2025 [January 21st, 2025]
- HomeKit Weekly: Combat dry winter air with the SwitchBot Smart Evaporative Humidifier - 9to5Mac - January 21st, 2025 [January 21st, 2025]
- The Google Home app is getting a big update, and it's good news for your security - TechRadar - January 21st, 2025 [January 21st, 2025]
- 6 ways Reolink's CES 2025 gadgets upped the ante for every other security camera this year - Android Police - January 21st, 2025 [January 21st, 2025]
- No Monthly Fee, the Eufy Security Floodlight Cam Is Now More Affordable Than Ever - Gizmodo - January 21st, 2025 [January 21st, 2025]
- Sound of Meteorite Hitting Earth Recorded by Security Camera Moments After Couple Left Home to Walk Their Dogs - PEOPLE - January 21st, 2025 [January 21st, 2025]
- Attempted burglary in Cranford highlights importance of home security - News 12 New Jersey - January 3rd, 2025 [January 3rd, 2025]
- Matthew Stafford had police inspect his home for potential security flaws amid burglaries - Rams Wire - January 3rd, 2025 [January 3rd, 2025]
- The Ring Stick Up Cam Pro drops to its all-time low price! - Android Authority - January 3rd, 2025 [January 3rd, 2025]
- Dallas Mavericks star Luka Doncic's home targeted in string of home burglaries - CBS News - January 3rd, 2025 [January 3rd, 2025]
- How Wireless Doorbell Kits Are Changing Home Security for the Better - openPR - January 3rd, 2025 [January 3rd, 2025]
- What UHNWs can learn about home security from 10 million London mansion heist - Spear's WMS - January 3rd, 2025 [January 3rd, 2025]
- Luxury Turns to Loss: Shafira Huangs Shocking Theft - Qhubo - January 3rd, 2025 [January 3rd, 2025]
- Home Tech Companies Are Peddling 'Affectionate Intelligence.' Should We Fall for It? - CNET - January 3rd, 2025 [January 3rd, 2025]
- The Best of Smart Home in 2024: The 10 Articles You Read the Most - How-To Geek - January 3rd, 2025 [January 3rd, 2025]
- The Top Home Security Mistakes to Stop Making in 2025 - CNET - January 3rd, 2025 [January 3rd, 2025]
- MagSafe Monday: LISEN delivers the strongest MagSafe magnet Ive found for the car - 9to5Mac - January 3rd, 2025 [January 3rd, 2025]
- The best floodlight and security camera combo I've tested is $70 off - ZDNet - January 3rd, 2025 [January 3rd, 2025]
- I invested in a subscription-less video doorbell, and it's paying off for my smart home - ZDNet - January 3rd, 2025 [January 3rd, 2025]
- NBA follows NFL in warning players on burglaries - ESPN - November 29th, 2024 [November 29th, 2024]
- Find heavily discounted security cameras and video doorbells ahead of Black Friday - Mashable - November 29th, 2024 [November 29th, 2024]
- This Floodlight Camera Has My Backyard Covered, and It's Under $100 for Black Friday - Lifehacker - November 29th, 2024 [November 29th, 2024]
- Get the ultimate home security this holiday season with Wyze starting at $17 - New York Post - November 29th, 2024 [November 29th, 2024]
- This Is the Best Black Friday Deal for an All-Purpose Security Cam I've Ever Seen - CNET - November 29th, 2024 [November 29th, 2024]
- NBA memo to players urges increased vigilance regarding home security following break-ins - Ashland Daily Press - November 29th, 2024 [November 29th, 2024]
- Find discounted security cameras and video doorbells ahead of Black Friday - Mashable - November 29th, 2024 [November 29th, 2024]
- The 4 Most Common Package Scams in 2024 -- and How to Stop Them - CNET - November 29th, 2024 [November 29th, 2024]
- Keep Your Home Protected During Your Holiday Travel With Up to 60% Off Blink Outdoor 4 Cams - CNET - November 21st, 2024 [November 21st, 2024]
- Editor's Note: Whats Old is New and Innovative Again? - SecurityInfoWatch - November 21st, 2024 [November 21st, 2024]
- Beef Up Your Home Security and Get Up to 77% Off With These Arlo Black Friday Deals - CNET - November 21st, 2024 [November 21st, 2024]
- Ive ditched my Nest Cams for a Chinese smart security brand you probably havent heard of - The Ambient - November 21st, 2024 [November 21st, 2024]
- Boost Your Home's Security With the Outdoor Roku Cam, Down to $20 for Black Friday - CNET - November 21st, 2024 [November 21st, 2024]
- Home Security Experts Share Important Insights About the Travis Kelce and Patrick Mahomes Burglaries - House Beautiful - November 21st, 2024 [November 21st, 2024]
- Infinity Symbol-Shaped Circular House Hits the Market for the Unique Price of $3,399,888 - SFGATE - November 21st, 2024 [November 21st, 2024]
- The Blink Outdoor 4 Home Security Cameras Are Cheaper Than Last Year's Black Friday Prices - Gizmodo - November 21st, 2024 [November 21st, 2024]
- Blink Mini 2 review: this home security camera is good price, but unimpressive performance might make you think twice - TechRadar - November 21st, 2024 [November 21st, 2024]
- How to Scrub Your Home Address Off the Internet and Keep It Off - CNET - November 21st, 2024 [November 21st, 2024]
- Defiant Smart Home Alarm Kit review: Just the basics - TechHive - November 21st, 2024 [November 21st, 2024]
- New Report Cites Six Outdoor Home Improvements That Enhance Wellness - Forbes - November 21st, 2024 [November 21st, 2024]
- 3 New AI Smart Home Features Arrive With Gemini and Google Nest - CNET - November 21st, 2024 [November 21st, 2024]
- Announcing the 2024 Readers' Choice Product Awards! - SecurityInfoWatch - November 21st, 2024 [November 21st, 2024]
- The Arlo 2K battery-powered security camera is 60% off before Black Friday - ZDNet - November 21st, 2024 [November 21st, 2024]
- Abilene Police expert offers advice on safeguarding your home during the holiday season - KTXS - November 21st, 2024 [November 21st, 2024]
- Travis Kelce and Taylor Swift take drastic measures after home burglary: 'They have 24-hour armed security staff' - Marca.com - November 21st, 2024 [November 21st, 2024]
- Smart Home Security Market will increase to USD 10.25 Billion by 2030 - openPR - November 21st, 2024 [November 21st, 2024]
- Want better home security? Dont miss these Reolink early Black Friday deals - Digital Trends - November 21st, 2024 [November 21st, 2024]
- An Interview With the Target & Home Depot Hacker - Krebs on Security - November 21st, 2024 [November 21st, 2024]
- Protect Your Home Title & Equity from Fraud with TripleLock Monitoring, Alerts & Restoration - ABC Action News Tampa Bay - November 12th, 2024 [November 12th, 2024]
- Wireless Home Security Camera Market is growing at a CAGR of 20% in the forecast period (2024-2031) - openPR - November 12th, 2024 [November 12th, 2024]
- Yes, Smart Homes Are Vulnerable to Cybercriminals. Here's What You Need to Know. - House Beautiful - November 12th, 2024 [November 12th, 2024]
- Limited-Time Deal: Protect Your Home or Business With a Ring Indoor Camera at Almost 40% Off - CNET - November 12th, 2024 [November 12th, 2024]
- The 3 Best Indoor Security Cameras of 2024 | Reviews by Wirecutter - Wirecutter, A New York Times Company - November 12th, 2024 [November 12th, 2024]
- Get home security cameras up to 60% off and feel extra cozy this winter - Mashable - November 12th, 2024 [November 12th, 2024]
- Resideo Unveils Honeywell Home FocusPRO Thermostats - SecurityInformed - November 12th, 2024 [November 12th, 2024]
- A Smart Before-the-Holidays Decision: Arlo and Allstate are Boosting Peace of Mind with New Home Security Bundle - IoT Evolution World - November 12th, 2024 [November 12th, 2024]
- The Google Nest Cam With Floodlight Is at Its Lowest Ever Price, but Not for Long - CNET - November 12th, 2024 [November 12th, 2024]
- Man shot by security guard at Home Depot in Northeast Philly - The Philadelphia Inquirer - November 12th, 2024 [November 12th, 2024]
- Keep Eyes on Your Home at All Times With a Blink Outdoor Cam for 60% Off - CNET - November 12th, 2024 [November 12th, 2024]
- A Letter to the Nation's New Leaders: Right Now, the American Dream of Homeownership Is in Crisis - SFGATE - November 12th, 2024 [November 12th, 2024]
- Get your tickets SECURED to Z100s Jingle Ball from Slomins Home Security! - iHeart - November 12th, 2024 [November 12th, 2024]
- We test a new home security package that couldn't be simpler to install - The Scotsman - November 12th, 2024 [November 12th, 2024]
- 6 Smart Gadgets That Will Instantly Upgrade Any Home's Lighting And Security - SlashGear - November 12th, 2024 [November 12th, 2024]
- Amazon has this Blink doorbell and security camera bundle on sale for the lowest price ever and its before - NJ.com - September 29th, 2024 [September 29th, 2024]
- This Blink Video Doorbell and security camera bundle is down to $59.99 at Amazon - TechRadar - September 29th, 2024 [September 29th, 2024]
- This new Eufy home security camera uses AI to add color to its night vision - TechRadar - September 29th, 2024 [September 29th, 2024]
- Did Jennifer Lopez and Ben Affleck Just Run Into More Trouble With Sale of $68 Million Marital Mansion? - SFGATE - September 29th, 2024 [September 29th, 2024]
- Sound the alarm! This 14-piece Ring smart security system is 40% off - Android Police - September 29th, 2024 [September 29th, 2024]
- Ring's Pan-Tilt Indoor Camera Just Crashed to a New Amazon Low Ahead of Prime Day - CNET - September 29th, 2024 [September 29th, 2024]
- The best home security cameras 2024: the smartest way to protect your home - TechRadar - September 29th, 2024 [September 29th, 2024]
- Bump Up Your Home Security With the Ultraloq Smart Lock for Only $99 - CNET - September 29th, 2024 [September 29th, 2024]
- This Early Prime Day Deal Will Score You a Blink Outdoor Camera for Over Half Off - CNET - September 29th, 2024 [September 29th, 2024]
- Supermodel Elle Macpherson Finally Sells Artsy Mansion at a Steep Discount After 2 Years on the Market - SFGATE - September 29th, 2024 [September 29th, 2024]
- Home security cameras: Learn how and where to install them for optimal protection - CNN Underscored - September 20th, 2024 [September 20th, 2024]
- Lions Dan Campbell has home address doxxed, creating series of security concerns - FOX 2 Detroit - September 20th, 2024 [September 20th, 2024]
- 2024's Best Outdoor Cameras: Vetted by Security Experts - Security.org - September 20th, 2024 [September 20th, 2024]
- Chilling home security footage shows what teen did seconds after 'fatally shooting her mother' - UNILAD - September 20th, 2024 [September 20th, 2024]
- Smart Home Security Camera Market is Expected to See a Growth of 13.2% CAGR from 2024 to 2034 | FMI - Future Market Insights - September 20th, 2024 [September 20th, 2024]
- Best Buy Deals of The Day: Save at Least $100 on Headphones, Home Security Systems, and Routers - PCMag - September 7th, 2024 [September 7th, 2024]