Hundreds Of Thousands Of Realtek-Powered Wi-Fi Devices Have Security Issues

It's revealed that serious vulnerabilities have been found on hundreds of different models of home networking devices made and sold by at least 65 different companies.

Affected models were released from 2010 and 2015, with some at least dating back to 2004.

According to a report by IoT Inspector, the German information-security firm that found the flaws, hackers are already exploiting the flaws.

They exploit the devices by making them part of their botnet networks. And not just that, as the flaws also pose privacy issues.

IoT Inspector explained that exploiting the flaws could also allow hackers to fully compromise the target device and execute arbitrary code with the highest level of privilege.

Realtek
Realtek SDK web interface. Most vendors and manufacturers use one of these web management binaries but change the appearance of the user interface so that it reflects their brand. (Credit: IoT Inspector)

It was discovered that all of the vulnerable devices are using Wi-Fi chips made by a Taiwanese company called Realtek.

IoT Inspector contacted Realtek and told them about the flaws back in May.

In August, Realtek released a number of patches.

However, Realtek didn't (cannot) fix all of its devices.

The reason is because Realtek cannot patch older chipsets, and also because patches it released should be implemented by the makers of the vulnerable devices, and may or may not be released as a firmware upgrade.

Realtek patched only devices that are about 5 years old.

Devices that are 10 years old will never get updates.

[block:block=87]
"Over the course of a research project focusing on a specific cable modem, we identified that the system was using a dual-SoC design. The main SoC was running a Linux system, while the second SoC – a dedicated Realtek RTL819xD chipset implementing all the access point functions – was found to be running another, stripped-down Linux system from Realtek."

"Realtek chipsets are found in many embedded devices in the IoT space. RTL8xxx SoCs – which provide wireless capabilities – are very common. We therefore decided to spend time identifying binaries running on the RTL819xD on our target device, which expose services over the network and are provided by Realtek themselves."

"By exploiting these vulnerabilities, remote unauthenticated attackers can fully compromise the target device and execute arbitrary code with the highest level of privilege."

"As awareness for supply chain transparency is on the rise among security experts, this example is a pretty good showcase of the vast implications of an obscure IoT supply chain. As opposed to recent supply chain attacks such as Kaseya or Solar Winds, where perpetrators went to great lengths to infiltrate the vendor’s release processes and place hidden backdoors in product updates, this example is far less sophisticated – and probably way more common."

"We got 198 unique fingerprints for devices that answered over UPnP. If we estimate that each device may have sold 5k copies (on average), the total count of affected devices would be close to a million."