20 popular router models are major security risks

In many homes, the router is the gateway to the wide and wild world of the internet. It’s that little gadget you connect your devices to for internet access. It’s an essential component in our internet-connected households and businesses.

But much like our computers and other smart appliances, your humble router is vulnerable to security threats, attacks and vulnerabilities.

Similar to several Netgear and D-Link router models, which were found to have security holes late last year, a number of Linksys routers were discovered to have still-unpatched vulnerabilities, which are exposing thousands of gadgets to potential attacks.

IOActive security consultant Tao Sauvage and security researcher Antide Petit revealed Wednesday 10 vulnerabilities in at least 20 Linksys router models were discovered late last year.

The vulnerabilities, which range from low- to high-risk severities, can allow attackers to overload the routers and force them to reboot via denial-of-service (DoS).

The flaws also allow hackers to snoop on sensitive information, including router firmware version, connected USB device data, Wi-Fi Protected Setup (WPS) PINs and even control settings.

Worst of all, attackers can exploit the vulnerabilities to gain authentication on the routers and execute root access commands for the creations of persistent backdoor access undetectable on the router’s management interface.

IOActive informed Linksys about the vulnerabilities in January and, in line with responsible disclosure, warned the company it will reveal the security flaws publicly after three months.

The affected Linksys router models are as follows:

  • EA2700
  • EA2750
  • EA3500
  • EA4500v3
  • EA6100
  • EA6200
  • EA6300
  • EA6350v2
  • EA6350v3
  • EA6400
  • EA6500
  • EA6700
  • EA6900
  • EA7300
  • EA7400
  • EA7500
  • EA8300
  • EA8500
  • EA9200
  • EA9400
  • EA9500
  • WRT1200AC
  • WRT1900AC
  • WRT1900ACS
  • WRT3200ACM

How to protect yourself

In response, Linksys released a security advisory warning users about the flaws and a few workarounds customers should do while the company prepares a patch.

Continue reading

5 password mistakes that will likely get you hacked

Passwords are your first line of defense against hackers and snoops trying to break into your accounts. You want your passwords to be rock solid so hackers don’t even have a hope of breaking them, but that often isn’t the case.

Continue reading

Free vs. paid Internet security software - What's the difference?

We are always getting emails and comments asking why anyone would pay for security software when there are plenty of free options available, and that’s a good question. In fact, we’ve covered some excellent free security options in the past. So, what does paid software give you that free options don’t? What this Komando.com report to find out!

3 ways to spot a malicious website

One of a hacker’s favorite tools for stealing your information is the phishing scam. Whether it’s through email, texts or on social media, sooner or later, you’ll run into messages that try to trick you into clicking on links to malicious websites.

Continue reading

Block Internet ads forever

A new gadget on Kickstarter could revolutionize the Internet by removing all ads from your Internet connection. The device will let users stream videos, surf the web and much more, all without making you watch ads first.

Password comedy

Everyone knows that strong passwords keep your data safe. But they can also be hard to remember! Stand-up comic Don Friesen sees the funny side of computer security.