{"id":256305,"date":"2021-08-02T12:45:43","date_gmt":"2021-08-02T10:45:43","guid":{"rendered":"https:\/\/www.borncity.com\/blog\/?p=256305"},"modified":"2022-02-21T08:18:05","modified_gmt":"2022-02-21T07:18:05","slug":"authentifizierungsschwachstelle-cve-2021-20090-bei-arcadyan-basierten-routern-und-modems","status":"publish","type":"post","link":"https:\/\/borncity.com\/blog\/2021\/08\/02\/authentifizierungsschwachstelle-cve-2021-20090-bei-arcadyan-basierten-routern-und-modems\/","title":{"rendered":"Authentifizierungsschwachstelle CVE-2021-20090 bei Arcadyan-basierten Routern und Modems"},"content":{"rendered":"<p><img decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" title=\"Sicherheit (Pexels, allgemeine Nutzung)\" src=\"https:\/\/borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Sicherheit_klein.jpg\" alt=\"Sicherheit (Pexels, allgemeine Nutzung)\" width=\"200\" align=\"left\" \/>[<a href=\"https:\/\/borncity.com\/win\/2021\/08\/02\/authentifizierungsschwachstelle-cve-2021-20090-bei-arcadyan-basierten-routern-und-modems\/\" target=\"_blank\" rel=\"noopener\">English<\/a>]Router und Modems des in Taiwan ans\u00e4ssigen Herstellers Arcadyan weisen eine Schwachstelle CVE-2021-20090 auf, mit der sich die Authentifizierung umgehen l\u00e4sst. Die Router und Modems werden unter vielen Handelsnamen von anderen Herstellern vertrieben. Bei der Telekom betrifft dies den Speedport Smart 3, bei Vodafone die EasyBox 802, 903 und 904. Hier ein kurzer \u00dcberblick \u00fcber die Schwachstelle.<\/p>\n<p><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg02.met.vgwort.de\/na\/23ab32d8dad5460599d5278352164f1d\" alt=\"\" width=\"1\" height=\"1\" \/>Das Ganze wurde von Tenable entdeckt und in <a href=\"https:\/\/web.archive.org\/web\/20210807213418\/https:\/\/de.tenable.com\/security\/research\/tra-2021-13?tns_redirect=true\" target=\"_blank\" rel=\"noopener\">diesem Dokument<\/a> beschrieben. Das CERT hat inzwischen <a href=\"https:\/\/kb.cert.org\/vuls\/id\/914124\" target=\"_blank\" rel=\"noopener\">diesen Sicherheitshinweis<\/a> zur Schwachstelle CVE-2021-20090 zum 20. Juli 2021 publiziert.<\/p>\n<p>In zahlreichen Routern verschiedener Hersteller, die die Arcadyan basierende Firmware verwenden, besteht eine Path Traversal-Schwachstelle (CVE-2021-20090). Diese Schwachstelle erm\u00f6glicht einem nicht authentifizierten Benutzer den Zugriff auf sensible Informationen, die normalerweise gesch\u00fctzt sind, und nun eine \u00c4nderung der Routerkonfiguration erm\u00f6glichen.<\/p>\n<p>Wird diese Sicherheitsl\u00fccke erfolgreich ausgenutzt, kann ein Angreifer auf Seiten zugreifen, f\u00fcr die sonst eine Authentifizierung erforderlich w\u00e4re. Ein nicht authentifizierter Angreifer k\u00f6nnte Zugang zu sensiblen Informationen erhalten, einschlie\u00dflich g\u00fcltiger Anfrage-Token, die f\u00fcr Anfragen zur \u00c4nderung von Router-Einstellungen verwendet werden k\u00f6nnten.<\/p>\n<p>Der Sicherheitsforscher, der die Schwachstelle entdeckte, ging zun\u00e4chst davon aus, dass die Schwachstelle auf einen Router-Hersteller beschr\u00e4nkt ist, und ver\u00f6ffentlichte seine Ergebnisse, entdeckte dann aber, dass das Problem in der auf Arcadyan basierenden Software besteht, die in Routern mehrerer Hersteller verwendet wird. Bei Tenable findet sich diese Liste betroffener Ger\u00e4te:<\/p>\n<div style=\"width: 640px; overflow-y: scroll;\">\n<table dir=\"ltr\" style=\"font-size: 10pt; font-family: arial; width: 813px; table-layout: fixed; border-style: none;\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"183\" \/>\n<col width=\"241\" \/>\n<col width=\"168\" \/><\/colgroup>\n<tbody>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Vendor&quot;}\"><span style=\"text-decoration: underline;\"><strong><code>Vendor<\/code><\/strong><\/span><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Device&quot;}\"><span style=\"text-decoration: underline;\"><strong><code>Device<\/code><\/strong><\/span><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Found on version&quot;}\"><span style=\"text-decoration: underline;\"><strong><code>Found on version<\/code><\/strong><\/span><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;ADB&quot;}\"><code>ADB<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;ADSL wireless IAD router&quot;}\"><code>ADSL wireless IAD router<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;1.26S-R-3P&quot;}\"><code>1.26S-R-3P<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Arcadyan&quot;}\"><code>Arcadyan<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;ARV7519&quot;}\"><code>ARV7519<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;00.96.00.96.617ES&quot;}\"><code>00.96.00.96.617ES<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Arcadyan&quot;}\"><code>Arcadyan<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;VRV9517&quot;}\"><code>VRV9517<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;6.00.17 build04&quot;}\"><code>6.00.17 build04<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Arcadyan&quot;}\"><code>Arcadyan<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;VGV7519&quot;}\"><code>VGV7519<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;3.01.116&quot;}\"><code>3.01.116<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Arcadyan &quot;}\"><code>Arcadyan<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;VRV9518&quot;}\"><code>VRV9518<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;1.01.00 build44&quot;}\"><code>1.01.00 build44<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;ASMAX&quot;}\"><code>ASMAX<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;BBR-4MG \/ SMC7908 ADSL&quot;}\"><code>BBR-4MG \/ SMC7908 ADSL<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:3,&quot;3&quot;:0.08}\"><code>0.08<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;ASUS &quot;}\"><code>ASUS<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;DSL-AC88U (Arc VRV9517)&quot;}\"><code>DSL-AC88U (Arc VRV9517)<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;1.10.05 build502&quot;}\"><code>1.10.05 build502<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;ASUS &quot;}\"><code>ASUS<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;DSL-AC87VG (Arc VRV9510)&quot;}\"><code>DSL-AC87VG (Arc VRV9510)<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;1.05.18 build305&quot;}\"><code>1.05.18 build305<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;ASUS &quot;}\"><code>ASUS<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;DSL-AC3100&quot;}\"><code>DSL-AC3100<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;1.10.05 build503&quot;}\"><code>1.10.05 build503<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;ASUS &quot;}\"><code>ASUS<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;DSL-AC68VG&quot;}\"><code>DSL-AC68VG<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;5.00.08 build272&quot;}\"><code>5.00.08 build272<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Beeline&quot;}\"><code>Beeline<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Smart Box Flash&quot;}\"><code>Smart Box Flash<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;1.00.13_beta4&quot;}\"><code>1.00.13_beta4<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;British Telecom&quot;}\"><code>British Telecom<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;WE410443-SA&quot;}\"><code>WE410443-SA<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;1.02.12 build02&quot;}\"><code>1.02.12 build02<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Buffalo&quot;}\"><code>Buffalo<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;WSR-2533DHPL2&quot;}\"><code>WSR-2533DHPL2<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:3,&quot;3&quot;:1.02}\"><code>1.02<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Buffalo&quot;}\"><code>Buffalo<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;WSR-2533DHP3&quot;}\"><code>WSR-2533DHP3<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:3,&quot;3&quot;:1.24}\"><code>1.24<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Buffalo&quot;}\"><code>Buffalo<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;BBR-4HG&quot;}\"><code>BBR-4HG<\/code><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Buffalo&quot;}\"><code>Buffalo<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;BBR-4MG&quot;}\"><code>BBR-4MG<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;2.08 Release 0002&quot;}\"><code>2.08 Release 0002<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Buffalo&quot;}\"><code>Buffalo<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;WSR-3200AX4S&quot;}\"><code>WSR-3200AX4S<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:3,&quot;3&quot;:1.1}\"><code>1.1<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Buffalo&quot;}\"><code>Buffalo<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;WSR-1166DHP2&quot;}\"><code>WSR-1166DHP2<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:3,&quot;3&quot;:1.15}\"><code>1.15<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Buffalo&quot;}\"><code>Buffalo<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;WXR-5700AX7S&quot;}\"><code>WXR-5700AX7S<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:3,&quot;3&quot;:1.11}\"><code>1.11<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Deutsche Telekom&quot;}\"><code>Deutsche Telekom<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Speedport Smart 3&quot;}\"><code>Speedport Smart 3<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;010137.4.8.001.0&quot;}\"><code>010137.4.8.001.0<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;HughesNet&quot;}\"><code>HughesNet<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;HT2000W&quot;}\"><code>HT2000W<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;0.10.10&quot;}\"><code>0.10.10<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;KPN&quot;}\"><code>KPN<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;ExperiaBox V10A (Arcadyan VRV9517)&quot;}\"><code>ExperiaBox V10A (Arcadyan VRV9517)<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;5.00.48 build453&quot;}\"><code>5.00.48 build453<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;KPN&quot;}\"><code>KPN<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;VGV7519&quot;}\"><code>VGV7519<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;3.01.116&quot;}\"><code>3.01.116<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;O2&quot;}\"><code>O2<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;HomeBox 6441&quot;}\"><code>HomeBox 6441<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;1.01.36&quot;}\"><code>1.01.36<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Orange&quot;}\"><code>Orange<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;LiveBox Fibra (PRV3399)&quot;}\"><code>LiveBox Fibra (PRV3399)<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;00.96.00.96.617ES&quot;}\"><code>00.96.00.96.617ES<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Skinny&quot;}\"><code>Skinny<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Smart Modem (Arcadyan VRV9517)&quot;}\"><code>Smart Modem (Arcadyan VRV9517)<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;6.00.16 build01&quot;}\"><code>6.00.16 build01<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;SparkNZ&quot;}\"><code>SparkNZ<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Smart Modem (Arcadyan VRV9517)&quot;}\"><code>Smart Modem (Arcadyan VRV9517)<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;6.00.17 build04&quot;}\"><code>6.00.17 build04<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Telecom (Argentina)&quot;}\"><code>Telecom (Argentina)<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Arcadyan VRV9518VAC23-A-OS-AM&quot;}\"><code>Arcadyan VRV9518VAC23-A-OS-AM<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;1.01.00 build44&quot;}\"><code>1.01.00 build44<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;TelMex&quot;}\"><code>TelMex<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;PRV33AC&quot;}\"><code>PRV33AC<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;1.31.005.0012&quot;}\"><code>1.31.005.0012<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;TelMex&quot;}\"><code>TelMex<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;VRV7006&quot;}\"><code>VRV7006<\/code><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Telstra&quot;}\"><code>Telstra<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Smart Modem Gen 2 (LH1000)&quot;}\"><code>Smart Modem Gen 2 (LH1000)<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;0.13.01r&quot;}\"><code>0.13.01r<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Telus&quot;}\"><code>Telus<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;WiFi Hub (PRV65B444A-S-TS)&quot;}\"><code>WiFi Hub (PRV65B444A-S-TS)<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;v3.00.20&quot;}\"><code>v3.00.20<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Telus&quot;}\"><code>Telus<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;NH20A&quot;}\"><code>NH20A<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;1.00.10debug build06&quot;}\"><code>1.00.10debug build06<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Verizon&quot;}\"><code>Verizon<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Fios G3100&quot;}\"><code>Fios G3100<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;1.5.0.10&quot;}\"><code>1.5.0.10<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Vodafone&quot;}\"><code>Vodafone<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;EasyBox 904&quot;}\"><code>EasyBox 904<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:3,&quot;3&quot;:4.16}\"><code>4.16<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Vodafone&quot;}\"><code>Vodafone<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;EasyBox 903&quot;}\"><code>EasyBox 903<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;30.05.714&quot;}\"><code>30.05.714<\/code><\/td>\n<\/tr>\n<tr>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;Vodafone&quot;}\"><code>Vodafone<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;EasyBox 802&quot;}\"><code>EasyBox 802<\/code><\/td>\n<td data-sheets-value=\"{&quot;1&quot;:2,&quot;2&quot;:&quot;20.02.226&quot;}\"><code>20.02.226<\/code><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>Das CERT\/CC empfiehlt, den Router auf die neueste verf\u00fcgbare Firmware-Version zu aktualisieren. Es wird au\u00dferdem empfohlen, die Remote-Administrationsdienste (WAN-seitig) auf jedem SoHo-Router zu deaktivieren und auch die Web-Schnittstelle im WAN zu deaktivieren.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[English]Router und Modems des in Taiwan ans\u00e4ssigen Herstellers Arcadyan weisen eine Schwachstelle CVE-2021-20090 auf, mit der sich die Authentifizierung umgehen l\u00e4sst. Die Router und Modems werden unter vielen Handelsnamen von anderen Herstellern vertrieben. Bei der Telekom betrifft dies den Speedport &hellip; <a href=\"https:\/\/borncity.com\/blog\/2021\/08\/02\/authentifizierungsschwachstelle-cve-2021-20090-bei-arcadyan-basierten-routern-und-modems\/\">Weiterlesen <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[731,426],"tags":[2038,4328],"class_list":["post-256305","post","type-post","status-publish","format-standard","hentry","category-gerate","category-sicherheit","tag-router","tag-sicherheit"],"_links":{"self":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/256305","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/comments?post=256305"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/256305\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/media?parent=256305"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/categories?post=256305"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/tags?post=256305"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}