Blog | G5 Cyber Security

IT Security Research by Pierre

A backdoor is present in several TOTOLINK products. This was confirmed by analyzing the latest firmwares and by testing the backdoor against live routers. We estimate there are =~ 50 000 routers affected by this backdoor. Using skt with arguments will send a TCP packet containing the command to the specified IP on port 5555. The binary can be used in x86_64 machines using QEMU: sudo chroot/qemu-mips-static./bin/skt. The problem is in the.seudo-code of sub_400B50: “TcpServer””]

Source: https://pierrekim.github.io/blog/2015-07-16-backdoor-and-RCE-found-in-8-TOTOLINK-products.html

Exit mobile version