Home
 » ISP News » 
Sponsored Links

AVM FRITZBox Broadband VDSL and ADSL Routers in Security Glitch

Tuesday, Jan 12th, 2016 (9:06 am) - Score 1,487

Owners of the German (AVM) made FRITZ!Box home broadband routers, specifically models 3272, 7272, 3370/3390/3490, 7312/7412, 7320/7330 SL, 736x SL and the 7490, should ensure that they have the latest firmware (v6.30 or newer) in order to fix a nasty security exploit.

FRITZ!Box routers have proven to be quite popular amongst more advanced users, not least due to their extensive feature sets. However the RedTeam Pentesting group has now published details of a security vulnerability that was first discovered last year (here), although it wasn’t made public until now in order to allow AVM time to fix the flaw.

Essentially the team “discovered that several models of the AVM FRITZ!Box are vulnerable to a stack-based buffer overflow, which allows attackers to execute arbitrary code on the device.” The term buffer overflow essentially means an approach that allows an attacker to exploit the devices memory by pushing more data than it can hold, which may in turn give them access to exploit memory on a normally secure part of the router.

RedTeam Pentesting Statement

After successful exploitation, attackers gain root privileges on the attacked device. This allows attackers to eavesdrop on traffic and to initiate and receive arbitrary phone calls, if the device is configured for telephony. Furthermore, backdoors may be installed to allow persistent access to the device.

In order to exploit the vulnerability, attackers either need to be able to connect to the service directly, i.e. from the LAN, or indirectly via an attacker-controlled website, that is visited by a FRITZ!Box user. This website can exploit the vulnerability via cross-site request forgery, connecting to the service via the attacked user’s browser. Therefore, it is estimated that the vulnerability poses a high risk.

The good news, as separately noted by The Register, is that AVM’s routers actually firewall the affected service. So unless the owner has stupidly disabled the routers firewall then any attacker would have to be able to connect directly to the device locally (LAN), which rules out a remote Internet-based exploit.

According to AVM’s German website the latest firmware (v6.50) was officially (non-beta) released on 10th December 2015, although the English language page for their high-end FRITZ!Box 7490 router still shows v6.30 as being the most recent release (27th August 2015) and it’s a similar story for their other devices. Luckily v6.30 is believed to fix the problem, but if you have anything older then now would be a good time to update.

Tags:
Mark-Jackson
By Mark Jackson
Mark is a professional technology writer, IT consultant and computer engineer from Dorset (England), he also founded ISPreview in 1999 and enjoys analysing the latest telecoms and broadband developments. Find me on X (Twitter), Mastodon, Facebook and .
Search ISP News
Search ISP Listings
Search ISP Reviews

Comments are closed

Cheap BIG ISPs for 100Mbps+
Community Fibre UK ISP Logo
150Mbps
Gift: None
Virgin Media UK ISP Logo
Virgin Media £26.00
132Mbps
Gift: None
Shell Energy UK ISP Logo
Shell Energy £26.99
109Mbps
Gift: None
Sky Broadband UK ISP Logo
100Mbps
Gift: None
Plusnet UK ISP Logo
Plusnet £27.99
145Mbps
Gift: None
Large Availability | View All
Cheapest ISPs for 100Mbps+
Gigaclear UK ISP Logo
Gigaclear £17.00
200Mbps
Gift: None
YouFibre UK ISP Logo
YouFibre £19.99
150Mbps
Gift: None
Community Fibre UK ISP Logo
150Mbps
Gift: None
BeFibre UK ISP Logo
BeFibre £21.00
150Mbps
Gift: £25 Love2Shop Card
Hey! Broadband UK ISP Logo
150Mbps
Gift: None
Large Availability | View All
The Top 15 Category Tags
  1. FTTP (5525)
  2. BT (3518)
  3. Politics (2541)
  4. Openreach (2298)
  5. Business (2264)
  6. Building Digital UK (2246)
  7. FTTC (2044)
  8. Mobile Broadband (1975)
  9. Statistics (1789)
  10. 4G (1666)
  11. Virgin Media (1621)
  12. Ofcom Regulation (1463)
  13. Fibre Optic (1395)
  14. Wireless Internet (1390)
  15. FTTH (1382)

Helpful ISP Guides and Tips

Promotion
Sponsored

Copyright © 1999 to Present - ISPreview.co.uk - All Rights Reserved - Terms , Privacy and Cookie Policy , Links , Website Rules , Contact
Mastodon