Critical OpenWrt Vulnerability Allowed Potential Malicious Firmware Distribution via Attended Sysupgrade
Join our
A critical vulnerability (CVE-2024-54143) in OpenWrt’s Attended Sysupgrade feature, used to create custom firmware images, could have been exploited to distribute malicious firmware packages.
What Is OpenWrt?
OpenWrt is a popular, highly customizable Linux-based operating system for embedded devices, especially routers and IoT hardware. It supports devices from major brands like ASUS, D-Link, Belkin, and many others, offering advanced features and greater flexibility compared to stock firmware.
The Vulnerability
Flatt Security researcher RyotaK discovered the issue during a routine home lab upgrade. The flaw, rated critical with a CVSS v4 score of 9.3, was found in OpenWrt’s Attended Sysupgrade (ASU) service. This feature simplifies upgrading devices by preserving packages and settings during firmware updates.
Two Main Issues Identified:
Command Injection via Package Names:
- The
sysupgrade.openwrt.orgservice processes inputs through commands in a containerized environment. - Improper handling of the
makecommand allowed arbitrary command injection via manipulated package names.
- The
Hash Truncation Vulnerability:
- The service uses a 12-character truncated SHA-256 hash (48 bits) for caching build artifacts.
- This makes brute-forcing collisions feasible, enabling attackers to reuse cache keys from legitimate firmware builds.
See Also: So, you want to be a hacker?
Exploit Demonstration
By combining these flaws, RyotaK no evidence of malicious activity during the 7-day log window they were able to review. However, they advised users to regenerate and reinstall firmware images to eliminate any potential risk
Trending:
Recommendations for Users
Upgrade Firmware Immediately:
- Perform an in-place upgrade with the same firmware version to ensure a clean, safe image.
Self-Hosted ASU Instances:
- If running a public ASU service, update it immediately to include the latest fixes.
Verify Downloads:
- While there is no evidence of compromised images from
downloads.openwrt.org, users should remain cautious and re-download firmware if necessary.
- While there is no evidence of compromised images from
Stay Updated:
- Follow OpenWrt announcements for further guidance and updates.
Trending:
🔖 Gespeicherte Artikel
tsecurity.de App
Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.
Community Radar & Live Chat
📡 Aktivitäten deiner Analysten
💡 Neues Thema oder Eilmeldung einreichen
Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.
SOCIAL SHARE CARD GENERATOR