- Joined
- Sep 16, 2018
- Messages
- 29,630
- Reaction score
- 7,953
For home router, when no port is opened, it should just reject everything from WAN-side right, I don't understand how can any decent router be vulnerable.
Google search CLS only show sg results, I guess it's like PUB water saving ticks where more ticks doesn't translates to better products.
Then you are too optimistic about router security. There are actually many vulnerabilties with the consumer routers in the market, even for those still supported by the vendor. Then there are still many consumers who are using outdated routers without security updates.
You can search the CVE website to know the problems. Interestingly Linksys seems to have less CVEs in recent years (2020-now)
https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=asus+routerhttps://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=tp-link+routerhttps://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=netgear+routerhttps://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=linksys+router
CSA CLS is just a Singapore government initiative. It may not be perfect as mentioned by @firesong. However, one of the basic requirement is to provide security updates up to certain date. So that at least helps a bit.
1) Example for Asus router
https://www.bleepingcomputer.com/ne...lops-blink-malware-attacks-targeting-routers/https://www.asus.com/content/ASUS-Product-Security-Advisory/04/01/2022 Security Advisory update for Cyclops Blink
Asus published firmware updates for the routers affected (many models) and advised the users not to use the EOLed product like the following.
RT-AC87U (EOL)
RT-AC66U (EOL)
RT-AC56U (EOL)
2) Example for Singtel Askey AP5100W mesh solution
https://medium.com/csg-govtech/bols...-from-close-proximity-to-uncover-f8f77dc3cd5dhttps://starlabs.sg/advisories/20/20-15357/https://starlabs.sg/advisories/20/20-25545/https://starlabs.sg/advisories/20/20-25546/
3) More discussions here:
https://forums.hardwarezone.com.sg/threads/router-security-alert.6721943/