PT-2024-9271 · Openwrt · Openwrt

Ry0Tak

·

Published

2024-12-06

·

Updated

2025-03-18

·

CVE-2024-54143

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: OpenWrt versions prior to 920c8a1
Description: The issue is related to the Attended SysUpgrade feature of OpenWrt, which allows for the injection of malicious firmware. This is due to a combination of command injection in the ImageBuilder service and the use of truncated SHA-256 hashes, making it feasible for an attacker to generate collisions and serve compromised images to users. The vulnerability could be exploited to distribute malicious firmware packages, potentially affecting over 1.7 million services.
Recommendations: Update to ASU version 920c8a1 to protect against the vulnerability. Verify the integrity of builds and only use official images from the OpenWrt website for safety. As a temporary workaround, consider restricting access to the vulnerable openwrt/asu server until a patch is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-10959
CVE-2024-54143
GHSA-R3GQ-96H6-3V7Q

Affected Products

Openwrt