Executive brief
The ASUS RT-N56U wireless router is susceptible to a flaw that allows a person on the same local network to crash the device's internet connection. By sending specific network probes, an attacker can cause a denial-of-service, effectively disconnecting the entire household or office from the internet. This requires the attacker to already have access to the local Wi-Fi or wired network.
Technical details
A denial-of-service (DoS) vulnerability exists in the ASUS RT-N56U router running firmware version 3.0.0.4.374_979. The issue is triggered when the device processes specific network packets associated with OS fingerprinting, such as those generated by the 'nmap -O' command. An attacker located on the adjacent network (LAN) can exploit this to crash the Wide Area Network (WAN) interface, leading to a disconnection from the ISP. No authentication is required to trigger the crash. While the root cause is not explicitly detailed in the advisory, it likely involves an unhandled exception or resource exhaustion in the network stack when processing malformed or unexpected TCP/IP sequences used for OS detection.
Affected products
- ASUS RT-N56U Wireless Router 3.0.0.4.374_979
Timeline
- 2017-01-30: disclosed
- 2017-01-30: advisory