A security researcher has disclosed a leak in several Asus routers which allows an attacker to fully take over the device and for which no patch is available yet. The vulnerability is caused by a service called infosrv that listens to commands on UDP port 9999 on the LAN port.

The infosrv service is used by Asus to make it easier to configure the router and to automatically search for routers on the local network. However infosrv doesn't properly check the MAC address from which the commands are coming. This makes it possible for attackers to bypass the router's authentication process and by sending packages to UDP port 9999 the attacker can send random commands to the router.
The vulnerabilities exists in the Asus RT-AC66U, RT-N66U and other routers with the most recent firmware. Security researcher Joshua Drake discovered the issue and advises Asus to remove the functionality that allows sending remote commands to the router. " Even if it were guarded with strong authentication, broadcasting a password to the entire local network isn't really something to be desired. If command execution is truly desired it should be provided via SSH or similar secure mechanism", according to Drake.
While waiting for Asus to release a patch that should close the loophole, users can take several measures by their own. Several users have posted information on how to disable the service and a way of block access to UDP port 9999. Alternatively it's also possible to disable the infosvr service by killing the process after each boot. That isn't actually hard, it can be done by exploiting the reported vulnerability, as Drake explains here.















