Number: IRCNE2015102653
Date: 2015/10/10
According to “zdnet”, Huawei will not patch a series of severe security flaws in more than a dozen commonly-used routers.
The Chinese networking giant reportedly told security researcher Pierre Kim that it will not provide patches for its B260a router -- widely used by internet providers across Europe and Africa -- because the device is no longer supported by the company.
The affected router is still provided to customers of numerous internet companies in dozens of countries, including Argentina, Ecuador, Kenya, Mali, and Tunisia -- all of which have mixed human rights records at best, or where government surveillance is commonplace at worst.
Kim, who discovered the flaws, said an attacker can launch a number of attacks against the router, including remote code execution and cross-site scripting attacks which can be used to deliver malware to target machines. Other attacks -- denial-of-service and site forgery attacks -- are also possible.
Those attacks can allow an attacker access to other devices on the network, or steal user credentials.
Huawei confirmed the flaws exist in the router, as well as in other devices in the B-series and E-series product lines manufactured in the past five years, but said its newer routers are not affected.
- 8