Backdoor on Linksys and Netgear Routers

    Not so long ago, we found a backdoor in D-Link , Tenda and Medialink routers , and 2 days ago, a github user with the nickname elvanderb lost access to the web interface of his router and decided to check what happened.
    As it turned out , some models of Linksys and Netgear routers (confirmed by Linksys WAG200G, Netgear DM111Pv2, Linksys WAG320N, and possibly others) also have a built-in backdoor, with more features than other manufacturers of routers.

    Backdoor listens on TCP port 32764 and has 13 different functions:
    1. Dump NVRAM
    2. Get a specific NVRAM parameter
    3. Set NVRAM
    4. Write to NVRAM (nvram-commit)
    5. Enable Wireless Bridge
    6. Show connection speed
    7. Shell
    8. Upload file
    9. Show firmware version
    10. Show IP on the WAN interface
    11. Restore factory settings
    12. Read / dev / mtdblock / 0 (bootloader?)
    13. Overwrite NVRAM

    You can read more about this backdoor in the author’s fun PDF.

    Also popular now: