Wednesday, April 29, 2015

Vulnerability in Realtek SDK Exposes Routers to Attacks

From Security Week:

Vulnerability in Realtek SDK Exposes Routers to Attacks

Routers from D-Link, TRENDnet and likely other vendors are vulnerable to remote code execution attacks due to a flaw in a component of the Realtek software development kit (SDK).

The issue was discovered by Ricky Lawshae, DVLabs security researcher and content developer at HP Enterprise Security. The expert reported his findings to HP’s Zero-Day Initiative (ZDI) in August 2014. Since Realtek hasn’t responded to any of ZDI’s attempts to report the vulnerability, the existence of the zero-day has been disclosed.

No comments:

Post a Comment