Exposed by Default: A Security Analysis of Home Router Default Settings


연구 분야: Analysis



학회: ASIA CCS '24: Proceedings of the 19th ACM Asia Conference on Computer and Communications Security


초록

With ubiquitous Internet connectivity, home routers have become a cornerstone of our digital lives, often deployed with minimal changes to the factory default settings. However, if left unexamined, these settings can pose risks to user security and privacy. To systematically evaluate potential risks, we developed a threat model-based framework and conducted a comprehensive analysis of 40 commercial off-the-shelf home routers, representative of recent models across 14 brands. We surveyed 81 parameters and behaviors including default and deep default settings. We identified a variety of security flaws including the exposure of IPv6 local devices due to a lack of firewall protection, vulnerable Wi-Fi security protocols, open Wi-Fi networks and trivial admin passwords for "plug-and-play" routers, and unencrypted firmware update communications. We also discovered concealed WPS PIN support --- at times associated with a trivial PIN. In total, we are reporting 30 exploitable vulnerabilities to the vendors. This paper highlights the need for heightened scrutiny of default router settings, providing valuable insights to both manufacturers and consumers for enhancing home network security. Our findings underscore the importance of meticulous device configuration, advocating for proactive measures from all stakeholders to mitigate the threats posed by insecure router default settings.


Author Profile
Lianying Zhao

Carleton University Ottawa Canada

Canada
Author Profile
Wei Zhang

Nanjing University of Posts and Telecommunications Nanjing China

Andorra
Author Profile
Junjian Ye

Nanjing University of Posts and Telecommunications Nanjing China

Andorra

📄 논문 정보

발행 연도 2024년
인용수 4
출판 국가 Andorra, China, Canada
사이트 ACM
좋아요 수 0

연관 논문 목록 (240건)