Skip to main content

Researchers find 10 vulnerabilities in 25 network routers supplied by Linksys

Linksys Max-Stream EA8300 review
Kevin Parrish/Digital Trends
After we pointed out a security issue with the web-based interface in our recent Linksys EA8300 router review, IOActive Labs reports it discovered 10 security vulnerabilities across 25 different Linksys routers, including the EA8300 unit we just reviewed. The issues range from low to high on a security level, six of which grant remote access to “unauthenticated” attackers.

In one example, hackers can use an affected router as a Denial-of-Service (DoS) tool. The hacker merely sends a few requests or “abuse” a specific API used by the browser-based backend. The router will then either become unresponsive or will reboot altogether. When that happens, router owners are locked out of the web-based interface and connected client devices can’t access the internet until the hacker stops the DoS attack.

Firmware flaws also enable hackers to collect “technical and sensitive” information about the router itself by bypassing the authentication protecting the onboard Common Gateway Interface (CGI) scripts, which enables the router to generate the browser-based interface. Information collected through this vulnerability include the firmware version, a list of connected USB devices, the firewall configuration, and more.

“Authenticated attackers can inject and execute commands on the operating system of the router with root privileges,” reports IOActive’s Taeo Sauvage. “One possible action for the attacker is to create backdoor accounts and gain persistent access to the router. Backdoor accounts would not be shown on the web admin interface and could not be removed using the Admin account.”

Sauvage and his co-researcher used the Shodan tool to discover that only around 7,000 vulnerable Linksys routers accessed the internet at the time of the report. However, that number does not include vulnerable routers that are running behind another network appliance or governed by strict firewall rules. That is also a global number spanning 25 different models, too.

That said, the majority of the vulnerable routers resides within the United States at 69 percent. Canada falls into second place with 10 percent while Hong Kong, Chile, Netherlands, Venezuela, Argentina, and Russia are each around one to two percent. The remaining 13 percent of the affected units fall within the “others” group.

What is not surprising is that around 11 percent of these devices rely on the default credentials provided by Belkin/Linksys, opening the door for hackers to simply log into the router and get full root access remotely. Most if not all of the affected routers are linked to a cloud account.

Belkin/Linksys is working on a firmware fix now. They provide a security advisory regarding the discovery although you will not find it splashed on the front cover of the Linksys website. It is also not openly listed on the website’s Support section. The only way we found the advisory was through a Google search, or by clicking on the link within Sauvage’s report.

Here are the routers in question:

EAxxxx Series

EA2700 EA2750 EA3500 EA4500 v3 EA6100
EA6200 EA6300 EA6350 v2 EA6350 v3 EA6400
EA6500 EA6700 EA6900 EA7300 EA7400
EA7500 EA8300 EA8500 EA9200 EA9400
EA9500


WRT Series

WRT 1200AC WRT 1900AC WRT 1900ACS WRT 3200ACM

Editors' Recommendations

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
What is CPU cache, and why is it so important for gaming?
AMD Ryzen 7 5800X3D chip.

AMD's 7800X3D and 7950X3D hold the top spot in CPUs for gaming, not because they have the most cores or the highest clock speeds, but because they have the most cache. But what is CPU cache, anyway? It's a small quantity of super-fast, rapid-access memory built into the chip itself, helping it get the data it needs for operations at blazing speed.

The returns aren't linear, though -- there's a reason the 7950X3D doesn't have additional cache on all of its cores. In fact, there are some downsides to having lots of extra cache to work with, even if it does help push up gaming performance. Here's everything you need to know about CPU cache.
What is CPU cache?

Read more
Best RAM deals: Discounted 16GB and 32GB from Corsair, Crucial
RAM inside the Starforge Navigator.

While a lot of focus tends to be put on things like the GPU and CPU, the truth is that the RAM is also quite important for performance, especially if you want to have a smooth day-to-day experience where opening several tabs doesn't crash everything. Of course, if you aren't very sure what sort of RAM to get, then it's worth checking out our guide on how to choose the best RAM for your PC as well as our guide on knowing how much RAM you need for a laptop, gaming PC, or tablet, both of which will give you a good sense of how much you should be spending.

To that end, if you're thinking of upgrading, we've collected some of our favorite RAM deals below, both for DDR4 and DDR5, so you can pick the RAM that best fits your needs.
Corsair VENGEANCE RGB PRO DDR4 16GB (2x8GB) --  $56, was $65

Read more
Best SSD deals: Samsung 990 Pro discounts
Samsung 990 PRO SSD over a dark background.

As recently as a decade ago, you would most likely be using an HDD, which tends to be quite slow and takes up an absolute tone of space, even the smaller form factor ones made for laptops. If you wanted something a bit more fancy, like a modern M.2 SSD, you'd be paying a huge premium even for smaller sizes like 256GB and 512GB. Luckily there have been huge leaps in technology and manufacturing, and these days you can get your hands on the best SSDs for a pretty good price. Not only does that mean that you can save space, but you can also load Windows and your applications a lot faster, something we expect to see in the best gaming PCs and gaming laptops.
Our favorite SSD deal

If you're looking for something that's top-of-the-line and won't break the bank, then the Samsung 990 PRO is probably the way to go. It has the newer PCIe 4.0 standard, which makes it a great PS5 SSD if you can get it a heatsink, and it has a read speed of 7450 Mbps and a write speed of 6900 Mbps, so it's lightning fast. The 2TB model here has been discounted down to just $190 from the original $250, so you're saving a pretty solid $60 in the process. There is a 1TB version that's cheaper if you don't think you need that much, as well as a 4TB model that's great for those who have a tendency to hoard data.

Read more