zCat on Nostr: I-O Data Confirms Zero-Day Attacks on Routers, Full Patches Pending Japanese device ...
I-O Data Confirms Zero-Day Attacks on Routers, Full Patches Pending
Japanese device maker I-O Data this week confirmed zero-day exploitation of critical flaws in multiple routers and warned that full patches won’t be available for a few weeks.
According to a warning from incident responders at JPCERT/CC, the most serious flaw opens the door for a remote attacker to disable the router’s firewall, execute commands, or alter configurations.
“The developer states that attacks exploiting these vulnerabilities have been observed,” according to the JPCERT/CC alert.
A separate bulletin from IO-Data documents three separate defects — CVE-2024-45841, CVE-2024-47133 and CVE-2024-52564 — and warns of additional information disclosure and command execution risks.
See more:
https://www.securityweek.com/i-o-data-confirms-zero-day-attacks-on-routers-full-patches-pending/#cybersecurity #zeroday #iodata
Published at
2024-12-06 08:22:03 CETEvent JSON
{
"id": "0d426248b27861631cc3594878fc01e9471d6c3d75a75bc61706e559a802ff9a",
"pubkey": "16fd26f00054f66151c6bd7925edef41586103af19d445f93f66f5e24b34427a",
"created_at": 1733469723,
"kind": 1,
"tags": [
[
"t",
"cybersecurity"
],
[
"t",
"zeroday"
],
[
"t",
"iodata"
],
[
"r",
"https://www.securityweek.com/i-o-data-confirms-zero-day-attacks-on-routers-full-patches-pending/"
]
],
"content": "I-O Data Confirms Zero-Day Attacks on Routers, Full Patches Pending\n\nJapanese device maker I-O Data this week confirmed zero-day exploitation of critical flaws in multiple routers and warned that full patches won’t be available for a few weeks.\n\nAccording to a warning from incident responders at JPCERT/CC, the most serious flaw opens the door for a remote attacker to disable the router’s firewall, execute commands, or alter configurations.\n\n“The developer states that attacks exploiting these vulnerabilities have been observed,” according to the JPCERT/CC alert.\n\nA separate bulletin from IO-Data documents three separate defects — CVE-2024-45841, CVE-2024-47133 and CVE-2024-52564 — and warns of additional information disclosure and command execution risks.\n\nSee more: https://www.securityweek.com/i-o-data-confirms-zero-day-attacks-on-routers-full-patches-pending/\n\n#cybersecurity #zeroday #iodata",
"sig": "6df2639eb46092f4613ee7c6d9e2ff0ca1827e3d857a02407b5f8b06ae23cfd9e332682d5c083706db8ad3831d19352c8237ca44d109397e2f2d0d893bbb1dc1"
}