ASUSWRT 3.0.0.4.376_1071 LAN Backdoor Command Execution

ASUSWRT version 3.0.0.4.376_1071 suffers from a remote command execution vulnerability. A service called “infosvr” listens on port 9999 on the LAN bridge. Normally this service is used for device discovery using the “ASUS Wireless Router Device Discovery Utility”, but this service contains a feature that allows an unauthenticated user on the LAN to execute commands less than or equal to 237 bytes as root. Source code is in asuswrt/release/src/router/infosvr. “iboxcom.h” is in asuswrt/release/src/router/shared.

Leave a Reply