Description Preview
A vulnerability was discovered in ASUS DSL-N14U-B1 1.1.2.3_805 devices where attackers can upload arbitrary file content by disguising it as a firmware update. By using the specific filename "Settings_DSL-N14U-B1.trx", attackers can bypass validation checks and cause the router to process the malicious file as a legitimate firmware update. This triggers shutdown procedures for various services as part of the normal update process, but since the file is not a valid firmware, these services remain in a non-functional state, resulting in a persistent denial of service condition.
Overview
This vulnerability (CVE-2021-3166) is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type). The issue affects ASUS DSL-N14U-B1 routers running firmware version 1.1.2.3_805. The vulnerability allows attackers to upload arbitrary files by exploiting insufficient validation in the firmware update mechanism. When a file with the name "Settings_DSL-N14U-B1.trx" is uploaded, the router initiates the update process regardless of the actual file content. This causes the router to shut down critical services in preparation for the update, but since the file is not a valid firmware image, these services remain disabled, effectively creating a persistent denial of service condition that requires manual intervention to resolve.
Remediation
- Update to the latest firmware version provided by ASUS if a patch is available.
- Implement network segmentation to restrict access to the router's management interface.
- Use strong, unique credentials for router administration.
- Monitor router logs for unusual activity or unauthorized access attempts.
- If affected by this attack, a hard reset of the router to factory defaults may be required to restore functionality.
- Consider implementing a firewall or other security measures to prevent unauthorized access to the router's administration interface.
- Regularly check for firmware updates from ASUS that address this vulnerability.
References
- Original vulnerability disclosure: https://kaisersource.github.io/dsl-n14u
- Detailed technical analysis: https://github.com/kaisersource/kaisersource.github.io/blob/main/_posts/2021-01-17-dsl-n14u.md
- CWE-434: Unrestricted Upload of File with Dangerous Type: https://cwe.mitre.org/data/definitions/434.html
- MITRE CVE Entry: CVE-2021-3166
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- Accommodation & Food ServicesAccommodation & Food Services
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting
- Arts, Entertainment & RecreationArts, Entertainment & Recreation
- ConstructionConstruction
- Educational ServicesEducational Services
- Finance and InsuranceFinance and Insurance
- Health Care & Social AssistanceHealth Care & Social Assistance
- InformationInformation
- Management of Companies & EnterprisesManagement of Companies & Enterprises
- ManufacturingManufacturing
- MiningMining
- Other Services (except Public Administration)Other Services (except Public Administration)
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services
- Public AdministrationPublic Administration
- Real Estate Rental & LeasingReal Estate Rental & Leasing
- Retail TradeRetail Trade
- Transportation & WarehousingTransportation & Warehousing
- UtilitiesUtilities
- Wholesale TradeWholesale Trade