> If users believe their router firmware may have been compromised, Linksys recommends that users download the latest available firmware from http://www.linksys.com/support/ and update your router. Is there a hardware feature that makes the firmware boot secure in a way that prevents the firmware from interfering with the update? Such as croning itself to reinstall the compromise when you're not looking? Or lying tha…
Linksys CherryBlossom Advisory
11–20 of 46 posts
Re: Linksys CherryBlossom Advisory
#12(And the latest available is newer than what's on my router now, so might as well.)
Re: Linksys CherryBlossom Advisory
#13> If users believe their router firmware may have been compromised, Linksys recommends that users download the latest available firmware from http://www.linksys.com/support/ and update your router. Is there a hardware feature that makes the firmware boot secure in a way that prevents the firmware from interfering with the update? Such as croning itself to reinstall the compromise when you're not looking? Or lying tha…
Re: Linksys CherryBlossom Advisory
#14> If users believe their router firmware may have been compromised, Linksys recommends that users download the latest available firmware from http://www.linksys.com/support/ and update your router. Is there a hardware feature that makes the firmware boot secure in a way that prevents the firmware from interfering with the update? Such as croning itself to reinstall the compromise when you're not looking? Or lying tha…
Need something with a TPM, like an Onhub/Google Wifi.
Because if they don't have this, then this is bad security advice against what is considered a targeted attack.
Re: Linksys CherryBlossom Advisory
#15So ... the latest available firmware for mine is from jan 2016. Clearly there would be no fix in that firmware. So the idea is that I'm installing a known/assumed/hoped "good" firmware, to replace the potentially bad firmware. Yes? (And the latest available is newer than what's on my router now, so might as well.)
Re: Linksys CherryBlossom Advisory
#16Re: Linksys CherryBlossom Advisory
#17I wonder if a factory reset is enough in all cases - the source for the factory reset has to be on the device itself. I haven't played with it much, but there are ways to persist after a reset on Android, I'd assume the same is possible here. Very happy to be corrected. Anyone know what the cheapest Linksys I could buy is, and whether these vulnerabilities have been released publicly?
If the security of your router is of concern to you I would recommend setting up your own FreeBSD+pfSense router. Another option is to setup a vpn server that all your devices connect to to access the internet. In that scenario it won't matter if your router is compromised because all traffic flowing through would be encrypted.
Nevermind the community, when it comes to vaguely complex things like IPTV and similar, support is either legacy or gone.
At this point OpenWRT is the only sane choice, at least it doesn't run everything as root and isn't going to shove off Multicast UDP packet forwarding support in the next year or two.
Re: Linksys CherryBlossom Advisory
#18> If users believe their router firmware may have been compromised, Linksys recommends that users download the latest available firmware from http://www.linksys.com/support/ and update your router. Is there a hardware feature that makes the firmware boot secure in a way that prevents the firmware from interfering with the update? Such as croning itself to reinstall the compromise when you're not looking? Or lying tha…
The firmware implant (aka flytrap) reproduces all of the router's normal functionality. On page 122 of the cherryblossom docs, it says that the firmware upgrade feature is implemented normally by the flytrap, and that if a user attempts to upgrade their router's firmware, it will overwrite the flytrap firmware.
Re: Linksys CherryBlossom Advisory
#19I wonder if a factory reset is enough in all cases - the source for the factory reset has to be on the device itself. I haven't played with it much, but there are ways to persist after a reset on Android, I'd assume the same is possible here. Very happy to be corrected. Anyone know what the cheapest Linksys I could buy is, and whether these vulnerabilities have been released publicly?
There were no vulnerabilities included in the cherryblossom leak. The firmware implant deployment instructions included in the leak don't mention using any vulnerabilities either.
Almost all of the devices listed in the cherryblossom leak are not being sold anymore.
Re: Linksys CherryBlossom Advisory
#20Isn't this a lie though? They do not mention remote compromise and I would bet dollars to doughnuts most old routers have RCE holes.
If you have any information about RCEs, Cherryblossom details we may have missed, or any other vulnerabilities in Linksys devices, please email me directly at benjamin.samuels at belkin.com