I see Asus has released firmware to fix the infosvr issue but what is the second security issue mentioned below? And does Merlin's firmware also have the latter patched?
Fixed infosvr security issue.
-Fixed Cross-site request forgery security issue
I have no idea what the second one is, so no, it's not patched. Since it's quite vague and does not refer to any specific CVE, it could be an undiscovered issue.
I wonder if that's the old man-in-the-middle vulnerability during an automatic code update?
You mean me ?
LOL....you gave me my good laugh for the day!
Security researcher Joshua Drake published an advisory warning that "all known firmware versions for applicable routers (RT-AC66U, RT-N66U, etc.) are assumed vulnerable."
The bug allows an attacker on the same network to take full administrative control of the router without the need for a password. The only known fix is to disable the troublesome infosvr service by killing the process when the affected device boots. That has to be performed each time the device restarts.
A working exploit was also published alongside the advisory.
While it may not be a major issue for those on private networks at home, those in offices or on public Wi-Fi are most at risk.
We've reached out to Asus but did not hear back at the time of writing.
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!