Telecom Tidbits
Jared's Network and Security Blog
  • Home
  • Telecom Corner
  • About
  • Contact
  • Donate
  • Site Index
  • Links

WordFence Advisory: Continued TR-069 Exploits

June 17, 2017 Jared Hall Internet Security

WordFence issued an advisory about continued Brute-Force login attempts from infected Home Routers.  Their original post is here.

This exploit was originally discovered by Checkpoint Software and is called “Misfortune Cookie”.   An attacker can send specially crafted HTTP cookies that can alter the router’s system state, tricking the router into treating the session as an “Administrator” session.  There are over 200 router models affected, including those from ASUS, D-Link, Edimax, Huawei, TP-Link, ZTE, and ZyXEL, to name a few.

The exploit exists in a chipset Software Development Kit (SDK) provided by AllegroSoft.  It provides an embedded webserver called RomPager that normally runs on TCP port 7547.  This provides TR-069 CPE WAN Management Protocol (CWMP) functions for telecom carriers.  This allows them to provision and manage your device:

 

WordFence offers a free scan tool so that you can check your router for this vulnerability.   If this test fails, it is advisable to turn off your router immediately to flush out any active exploit in progress, then call your phone or cable company immediately.

 

« Of the NSA & Russian Election Hacks » Fortinet: Guide To The Threat Landscape

Tools & Downloads

Download Center

Categories

Good Reads (PDF)

Recent Posts

  • PayPal Woes and Degenerative AI
  • A Pathetic Defense of Julian Assange
  • Damned if you do. Damned if you don’t.
  • ProtonMail? Not Worth an Electron!
  • Give it a REST: Serious WordPress Bugs
$
Select Payment Method
Personal Info

Donation Total: $20.00

↑

  • Home
  • Telecom Corner
  • About
  • Contact
  • Donate
  • Site Index
  • Links
Temporal Based Intelligence © 2017