Source |
The Hacker News |
Identifiant |
8624676 |
Date de publication |
2024-12-13 22:18:00 (vue: 2024-12-13 18:08:10) |
Titre |
Critical OpenWrt Vulnerability Exposes Devices to Malicious Firmware Injection |
Texte |
A security flaw has been disclosed in OpenWrt\'s Attended Sysupgrade (ASU) feature that, if successfully exploited, could have been abused to distribute malicious firmware packages.
The vulnerability, tracked as CVE-2024-54143, carries a CVSS score of 9.3 out of a maximum of 10, indicating critical severity. Flatt Security researcher RyotaK has been credited with discovering and reporting the
A security flaw has been disclosed in OpenWrt\'s Attended Sysupgrade (ASU) feature that, if successfully exploited, could have been abused to distribute malicious firmware packages.
The vulnerability, tracked as CVE-2024-54143, carries a CVSS score of 9.3 out of a maximum of 10, indicating critical severity. Flatt Security researcher RyotaK has been credited with discovering and reporting the |
Notes |
★★★
|
Envoyé |
Oui |
Condensat |
2024 54143 abused asu attended been carries could credited critical cve cvss devices disclosed discovering distribute exploited exposes feature firmware flatt flaw has have indicating injection malicious maximum openwrt out packages reporting researcher ryotak score security severity successfully sysupgrade tracked vulnerability |
Tags |
Vulnerability
|
Stories |
|
Move |
|