Latest News

  • Home
  • Electronics & Gadgets
  • Wi-Fi Firmware Security Bug Could Affect Billions of Game Consoles, Laptops, and More, Researcher Says
Wi-Fi Firmware Security Bug Could Affect Billions of Game Consoles, Laptops, and More, Researcher Says
Tuesday, January 22, 2019 IST
Wi-Fi Firmware Security Bug Could Affect Billions of Game Consoles, Laptops, and More, Researcher Says

HIGHLIGHTS
 
*The security vulnerability was discovered by research firm Embedi
*Billions of Wi-Fi-enabled devices are potentially affected
*An attacker would need to be in physical proximity of a target device

 
 

Security research firm Embedi has published a report about severe security vulnerabilities it has found in several Wi-Fi controller chips used by billions of the world's most popular Wi-Fi-enabled products. These include the Microsoft Xbox One, Sony PlayStation 4, and some laptop and smartphone models as well as several routers, embedded devices, and network access hardware. The bugs in question allow malicious attackers to force Wi-Fi-enabled devices to execute arbitrary code simply by being turned on, without requiring any action on the part of the device owner or user. The attack is triggered whenever an affected device searches for available Wi-Fi networks, which is something that is set to happen automatically and repeatedly.
 
The root of the problem lies in a real-time operating system called ThreadX, which is used as the embedded firmware for many Wi-Fi controllers including the popular Marvell Avastar family used as the subject of Embedi's research. There are four vulnerabilities in total, which exploit a memory corruption bug referred to as a “block pool overflow” in order to introduce the malicious code onto a device.
 
One of these bugs is specific to the widely used Marvell Avastar 88W8897 Wi-Fi controller, but the others can affect any device based on ThreadX using the same techniques. Embedi cites ThreadX's own website as the source of its statement that over six billion devices have been deployed running this firmware.
 
Because affected Wi-Fi devices are set to scan for new networks every five minutes, regardless of whether or not they are already connected to a Wi-Fi network, this bug “provides an opportunity to exploit devices literally with zero-click interaction at any state of wireless connection”, according to the published report. Once malicious code is introduced onto the Wi-Fi controller, other techniques could be exploited to send data to the device's application processor.
 
A hypothetical attacker would not need to know a target's Wi-Fi SSID name or password, and the target device only needs to be turned on. The attacker would need to broadcast the malicious packets from within physical range of the target device, though.

 
 
 
 
 

Related Topics

 
 
 

Trending News & Articles

 Article
Tata Harrier’s 7-seater Version H7X Will Be Quite Different – Report

Tata Harrier’s three-row seat version in works, details out  

Recently posted . 2K views . 0 min read
 

 Article
How to make you car as silent as a Rolls Royce inside

Rolls Royce cars are extremely luxurious. While there are many expensive pieces of equipment in Rolls Royce cars, their most relaxing feature is the silence that ...

Recently posted . 2K views . 2 min read
 

 Article
India's Top 5 Mobile Charger manufacturer Brand 2019

The following list of India's Top 5 Mobile Charger manufacture Brand 2019  

Recently posted . 2K views . 0 min read
 

 Article
Mahindra XUV300 vs Maruti Brezza, Ford EcoSport, Tata Nexon – Price

XUV300 is the latest entrant in the compact SUV segment.

Recently posted . 2K views . 0 min read
 

 
 

More in Electronics & Gadgets

 Article
BlackBerry KEY2 LE specs and photos are out

Old-school BlackBerry fans were excited to see TCL releasing a follow-up to the original BlackBerry Keyone and it turned out to be a pretty decent smartphone. How...

Recently posted. 701 views . 2 min read
 

 Article
Samsung Galaxy S10 might have a piezoelectric speaker, like the Mi Mix

Samsung is reportedly working on its own under the display speaker technology, called Sound on Display.

Recently posted. 588 views . 0 min read
 

 Article
Google Maps gets new safety feature in India, to alert passengers if cab driver deviates from route

The new safety feature is now available to Android users in India using the latest version of Google Maps.  

Recently posted. 649 views . 0 min read
 

 Video
Amazing Domino Effect



Recently posted . 800 views
 

 Video
10 Cool Toys Every Kid Needs



Recently posted . 1K views
 

 Reviews
Heelight Review: Sound controlled smart bulb



Recently posted . 1K views . 26 min read
 

 Article
KTM 390 Adventure revealed at EICMA 2019

The 390 Adventure will be launched in India at IBW in December.

Recently posted. 658 views . 0 min read
 

 Article
Google Working on Social Photos App That Allows Groups to Share, Edit Pictures

It seems like Apple is not the only tech massive to be operating on simplified media apps, as Google is presently operating on...

Recently posted. 840 views . 14 min read
 

 
 
 

   Prashnavali

  Thought of the Day

"Think of the most attractive person you know. Even that person, at some point, has had raging diarrhoea."
Anonymous

Be the first one to comment on this story

Close
Post Comment
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST


ads
Back To Top