Major security issues found in Cisco routers
Security researchers have compromised Cisco's 1001-X series router
Researchers from the security firm Red Balloon have discovered a remote attack method that could allow hackers to take over Cisco's 1001-X series router and compromise all of the data and commands sent through the device.
To compromise the company's routers, the researchers exploited two vulnerabilities. The first is a bug in Cisco's IOS operating system which would allow an attacker to gain root access to the devices, though this vulnerability can be fixed through a software patch.
The second vulnerability required the researchers to first gain root access to a Cisco router and from there, they were able to bypass the device's security protection known as Trust Anchor. The network hardware maker has implemented this security feature in almost all of its enterprise devices since 2013.
- Is your router a cybersecurity risk?
- Vulnerabilities discovered in Verizon routers leave millions of consumers at risk
- How to install Cisco VPN client on Windows 10
Since Red Balloon was able to bypass Trust Anchor on Cisco's 1001-X series router by using device-specific modifications, it means that similar tactics could potentially be used on hundreds of millions of the company's devices around the world including everything from enterprise routers to network switches and even firewalls.
Trust Anchor
The tactics employed by Red Balloon could even possibly be used to fully compromise networks running on Cisco's routers which are used by businesses and governments all over the world.
The security firm's founder and CEO, Ang Cui provided further insight on the remote attack method its researchers discovered, saying:
“We’ve shown that we can quietly and persistently disable the Trust Anchor. That means we can make arbitrary changes to a Cisco router and the Trust Anchor will still report that the device is trustworthy. Which is scary and bad, because this is in every important Cisco product. Everything.”
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Cisco responded to the news by announcing a patch for the IOS remote control vulnerability and the company says it will provide fixes for all product families that are potentially vulnerable to secure enclave attacks. However, all of its fixes are still months from release and there are currently no workarounds.
When the patched do become available though, they won't be able to be pushed remotely and will require an on-premise reprogramming.
- We've also highlighted the best small business routers
Via Wired
After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home.