Twiglets
Senior Member
For information: (Includes many ASUS Routers)
Wreckin' routers
Last month, Kaspersky warned of advanced malware, dubbed Slingshot, that uses routers to infect networks. Well, here's some more along those lines. A report [PDF]* by Akamai discusses software nasties leveraging vulnerable Universal Plug and Play (UPnP) services offered by routers and gateways to press-gang at least 65,000 boxes.
In all, Akamai estimated that around five million routers could be vulnerable to hijacking via UPnP exploits: miscreants can use the flaws to rewrite networking tables, and turn devices into proxy servers. It has compiled a list of 400 router models from 73 manufacturers that are hackable, and if you've got one of these then it's time to either upgrade your kit or mitigate the risk.
From https://www.theregister.co.uk/2018/04/14/security_roundup/
*https://www.akamai.com/us/en/multim...at-proxies-via-nat-injections-white-paper.pdf
TL;DR
Make sure you block UPnP from the 'Internet/WAN' side, if you do not need to use it.
(Should NOT need to use it 'Internet/WAN' side AFAIK ...... sure to be told otherwise real soon )
P.S. Don't know if Asuswrt-Merlin effectively fixes this or not, apologies if it does.
Wreckin' routers
Last month, Kaspersky warned of advanced malware, dubbed Slingshot, that uses routers to infect networks. Well, here's some more along those lines. A report [PDF]* by Akamai discusses software nasties leveraging vulnerable Universal Plug and Play (UPnP) services offered by routers and gateways to press-gang at least 65,000 boxes.
In all, Akamai estimated that around five million routers could be vulnerable to hijacking via UPnP exploits: miscreants can use the flaws to rewrite networking tables, and turn devices into proxy servers. It has compiled a list of 400 router models from 73 manufacturers that are hackable, and if you've got one of these then it's time to either upgrade your kit or mitigate the risk.
From https://www.theregister.co.uk/2018/04/14/security_roundup/
*https://www.akamai.com/us/en/multim...at-proxies-via-nat-injections-white-paper.pdf
TL;DR
Make sure you block UPnP from the 'Internet/WAN' side, if you do not need to use it.
(Should NOT need to use it 'Internet/WAN' side AFAIK ...... sure to be told otherwise real soon )
P.S. Don't know if Asuswrt-Merlin effectively fixes this or not, apologies if it does.