Vulnerability Affects Hundreds of Thousands of IoT Devices

Here’s something to be cheery on Christmas Day —a vulnerability affecting a web server that’s been embedded in hundreds of thousands of IoT devices.

The said vulnerability affects GoAhead, a tiny web server package created by Embedthis Software LLC, a company based in Seattle, USA.

This tiny web server is quite popular with hardware vendors since it can run on devices with limited resources, such as Internet of Things (IoT) devices, routers, printers, and other networking equipment.

This week, security researchers from Australian company Elttam discovered a way execute malicious code remotely on devices using the GoAhead web server package.

The technical details of this vulnerability, which is tracked as CVE-2017-17562, are explained in a technical write-up here.

Attackers can exploit this flaw if CGI is enabled and a CGI program is dynamically linked, which is quite a common configuration options.

Elttam reported the flaw to Embedthis, and the server released a patch. All GoAhead versions before GoAhead 3.6.5 are presumed vulnerable, albeit researchers only verified the flaw on GoAhead versions going back to version 2.5.0 only.

read more at bleepingcomputer.com

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top