Home
 » ISP News » 
Sponsored Links

AVM FRITZBox Broadband VDSL and ADSL Routers in Security Glitch

Tuesday, Jan 12th, 2016 (9:06 am) - Score 1,527

Owners of the German (AVM) made FRITZ!Box home broadband routers, specifically models 3272, 7272, 3370/3390/3490, 7312/7412, 7320/7330 SL, 736x SL and the 7490, should ensure that they have the latest firmware (v6.30 or newer) in order to fix a nasty security exploit.

FRITZ!Box routers have proven to be quite popular amongst more advanced users, not least due to their extensive feature sets. However the RedTeam Pentesting group has now published details of a security vulnerability that was first discovered last year (here), although it wasn’t made public until now in order to allow AVM time to fix the flaw.

Advertisement

Essentially the team “discovered that several models of the AVM FRITZ!Box are vulnerable to a stack-based buffer overflow, which allows attackers to execute arbitrary code on the device.” The term buffer overflow essentially means an approach that allows an attacker to exploit the devices memory by pushing more data than it can hold, which may in turn give them access to exploit memory on a normally secure part of the router.

RedTeam Pentesting Statement

After successful exploitation, attackers gain root privileges on the attacked device. This allows attackers to eavesdrop on traffic and to initiate and receive arbitrary phone calls, if the device is configured for telephony. Furthermore, backdoors may be installed to allow persistent access to the device.

In order to exploit the vulnerability, attackers either need to be able to connect to the service directly, i.e. from the LAN, or indirectly via an attacker-controlled website, that is visited by a FRITZ!Box user. This website can exploit the vulnerability via cross-site request forgery, connecting to the service via the attacked user’s browser. Therefore, it is estimated that the vulnerability poses a high risk.

The good news, as separately noted by The Register, is that AVM’s routers actually firewall the affected service. So unless the owner has stupidly disabled the routers firewall then any attacker would have to be able to connect directly to the device locally (LAN), which rules out a remote Internet-based exploit.

According to AVM’s German website the latest firmware (v6.50) was officially (non-beta) released on 10th December 2015, although the English language page for their high-end FRITZ!Box 7490 router still shows v6.30 as being the most recent release (27th August 2015) and it’s a similar story for their other devices. Luckily v6.30 is believed to fix the problem, but if you have anything older then now would be a good time to update.

Tags:
Mark-Jackson
By Mark Jackson
Mark is a professional technology writer, IT consultant and computer engineer from Dorset (England), he also founded ISPreview in 1999 and enjoys analysing the latest telecoms and broadband developments. Find me on X (Twitter), Mastodon, Facebook, BlueSky, Threads.net and .
Search ISP News
Search ISP Listings
Search ISP Reviews

Comments are closed

Cheap BIG ISPs for 100Mbps+
Community Fibre UK ISP Logo
200Mbps
Gift: None
Youfibre UK ISP Logo
Youfibre £23.99
150Mbps
Gift: None
Plusnet UK ISP Logo
Plusnet £24.99
145Mbps
Gift: £140 Reward Card
Vodafone UK ISP Logo
Vodafone £25.00
150Mbps
Gift: None
TalkTalk UK ISP Logo
TalkTalk £25.00
152Mbps
Gift: None
Large Availability | View All
Cheap Unlimited Mobile SIMs
iD Mobile UK ISP Logo
iD Mobile £16.00
Contract: 24 Months
Data: Unlimited
Talkmobile UK ISP Logo
Talkmobile £16.95
Contract: 1 Month
Data: Unlimited
Smarty UK ISP Logo
Smarty £17.00
Contract: 1 Month
Data: Unlimited
ASDA Mobile UK ISP Logo
ASDA Mobile £19.00
Contract: 24 Months
Data: Unlimited
Three UK ISP Logo
Three £20.00
Contract: 24 Months
Data: Unlimited
Cheapest ISPs for 100Mbps+
toob UK ISP Logo
toob £18.00
150Mbps
Gift: None
Gigaclear UK ISP Logo
Gigaclear £19.00
300Mbps
Gift: None
Community Fibre UK ISP Logo
200Mbps
Gift: None
Beebu UK ISP Logo
Beebu £23.00
100 - 160Mbps
Gift: None
Hey! Broadband UK ISP Logo
150Mbps
Gift: None
Large Availability | View All
Promotion
Sponsored

Copyright © 1999 to Present - ISPreview.co.uk - All Rights Reserved - Terms , Privacy and Cookie Policy , Links , Website Rules , Contact
Mastodon