Close Menu
    Facebook LinkedIn YouTube Instagram X (Twitter)
    Blue Tech Wave Media
    Facebook LinkedIn YouTube Instagram X (Twitter)
    • Home
    • Leadership Alliance
    • Exclusives
    • Internet Governance
      • Regulation
      • Governance Bodies
      • Emerging Tech
    • IT Infrastructure
      • Networking
      • Cloud
      • Data Centres
    • Company Stories
      • Profiles
      • Startups
      • Tech Titans
      • Partner Content
    • Others
      • Fintech
        • Blockchain
        • Payments
        • Regulation
      • Tech Trends
        • AI
        • AR/VR
        • IoT
      • Video / Podcast
    Blue Tech Wave Media
    Home » OpenWrt urges users to upgrade after security flaws found
    0830-vulnerability management
    0830-vulnerability management
    IT Infrastructure

    OpenWrt urges users to upgrade after security flaws found

    By Tanee ShaoDecember 10, 2024Updated:December 13, 2024No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email
    • OpenWrt urges users to upgrade firmware after security flaws in ASU server.
    • Two vulnerabilities could allow attackers to serve compromised firmware images.

    What happened: OpenWrt security flaws

    OpenWrt users are advised to upgrade their firmware images to the same version after a security issue was reported last week. The vulnerability, discovered in the project’s attended sysupgrade server (ASU), could potentially allow attackers to inject malicious firmware through a combination of two flaws.

    The first flaw, a command injection bug in the ‘openwrt/imagebuilder’ image, allows attackers to inject malicious package names, creating fake firmware images signed with a legitimate build key. The second flaw, a weak hash vulnerability (CVE-2024-54143), occurs because the SHA-256 hash used in the build request is truncated, reducing its complexity and enabling hash collisions. These vulnerabilities could allow attackers to deliver compromised firmware to unsuspecting users. Although the risk of compromised images is low, OpenWrt recommends users upgrade to the same version to mitigate any potential threats. Users hosting public ASU instances are urged to apply the fixes immediately.

    OpenWrt assured users that official images and custom builds from 24.10.0-rc2 remain unaffected. However, older builds not checked due to automatic cleanup procedures may still pose a risk. OpenWrt issued the advisory shortly after announcing OpenWrt One. The Software Freedom Conservancy developed this new hardware platform.

    Also read: 9 common types of firmware
    Also read: GitHub Vulnerability Exposes 4,000+ to RepoJacking Attack  

    Why it is important

    The security flaw in OpenWrt’s sysupgrade server (ASU) makes it crucial for users to upgrade their firmware to the same version. The vulnerability could allow attackers to inject malicious firmware using two issues: a command injection bug and a weak hash vulnerability. The command injection allows malicious package names to create fake firmware images. The weak hash makes it easier for attackers to generate collisions and serve compromised images.

    Although the risk of a successful attack is low, OpenWrt recommends upgrading to eliminate any potential threats. Users with public ASU instances should update immediately. Official images and recent custom builds remain unaffected, but older builds could still be at risk. This issue highlights the need for timely updates and vigilance in maintaining the integrity of the system. The advisory comes just after the announcement of OpenWrt One, underscoring the importance of securing both software and hardware platforms.

    Firmware OpenWrt vulnerability
    Tanee Shao

    Tanee Shao is an intern reporter at BTW Media, having studied at Kings College of London. She specialises in fintech. Contact her at t.shao@btw.media.

    Related Posts

    Datum’s MCR2 delivers Next-Gen data capacity in Manchester

    July 7, 2025

    Temasek Polytechnic: Shaping future innovators

    July 7, 2025

    Lelantos: Tackles home WiFi gaps with enterprise solutions

    July 7, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    CATEGORIES
    Archives
    • July 2025
    • June 2025
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024
    • November 2024
    • October 2024
    • September 2024
    • August 2024
    • July 2024
    • June 2024
    • May 2024
    • April 2024
    • March 2024
    • February 2024
    • January 2024
    • December 2023
    • November 2023
    • October 2023
    • September 2023
    • August 2023
    • July 2023

    Blue Tech Wave (BTW.Media) is a future-facing tech media brand delivering sharp insights, trendspotting, and bold storytelling across digital, social, and video. We translate complexity into clarity—so you’re always ahead of the curve.

    BTW
    • About BTW
    • Contact Us
    • Join Our Team
    TERMS
    • Privacy Policy
    • Cookie Policy
    • Terms of Use
    Facebook X (Twitter) Instagram YouTube LinkedIn

    Type above and press Enter to search. Press Esc to cancel.