Author Topic: Wi-Fi inspector and Router vulnerabilities - possible false detection?  (Read 2740 times)

0 Members and 1 Guest are viewing this topic.

Online NON

  • Japanese User
  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5489
  • Whatever will be, will be.
Hello,

I got a report in the Japanese forum that Wi-Fi inspector detected router vulnerabilities "CVE-2013-0229" and "CVE-2013-0230", which seems like false detections because the router in question uses non-vulnerable version of library.
https://forum.avast.com/index.php?topic=203347.0

I also found that Wi-Fi inspector flagged my router as vulnerable for "CVE-2012-5958", while it didn't find this a month ago.

My router (PE-500KI) is built in 2014 and updated in 2016, the OP in the Japanese forum uses newer one (Aterm WG1200HS, built in 2015 and updated in 2017). So I don't think they have years-old vulnerabilities.
« Last Edit: June 05, 2017, 04:05:10 PM by NON »
Desktop: Win10 Pro 22H2 64bit / Core i5-7400 3.0GHz / 32GB RAM / Avast 23 Premium Beta(Icarus) / Comodo Firewall
Notebook: Win10 Pro 22H2 64bit / Core i5-3340M 2.7GHz / 12GB RAM / Avast 23 Free / Windows Firewall Control
Server: Win11 Pro 23H2 64bit / Core i3-4010U 1.7GHz / 12GB RAM / Avast One 23 Essential

Avast の設定について解説しています。よろしければご覧ください。


Online NON

  • Japanese User
  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5489
  • Whatever will be, will be.
As I stated above WG1200HS uses non-vulnerable version of library according to its manual.
Also, the page you quoted did not say anything about vulnerabilities, it just shows what has changed in latest firmware. There are several releases before the latest one and some of them contains security fixes.

Why I started this topic is I can see sudden increase of similar reports in Japan that suggests these detections might be false.
« Last Edit: June 09, 2017, 03:03:10 PM by NON »
Desktop: Win10 Pro 22H2 64bit / Core i5-7400 3.0GHz / 32GB RAM / Avast 23 Premium Beta(Icarus) / Comodo Firewall
Notebook: Win10 Pro 22H2 64bit / Core i5-3340M 2.7GHz / 12GB RAM / Avast 23 Free / Windows Firewall Control
Server: Win11 Pro 23H2 64bit / Core i3-4010U 1.7GHz / 12GB RAM / Avast One 23 Essential

Avast の設定について解説しています。よろしければご覧ください。

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Read the release notes.
There is no mentioning about it being fixed after the CVE was published in any of the firmware updates.

Online NON

  • Japanese User
  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5489
  • Whatever will be, will be.
Read the release notes.
There is no mentioning about it being fixed after the CVE was published in any of the firmware updates.
Yes, I read the release notes that why I knew there are other releases that contains other fixes.
If they uses non-vulnerable libraries in the first place, there is no chance the corresponding CVE appears in it, isn't it?

BTW there are links to other documents that describes what vulnerabilities were fixed in certain updates. Some have CVEs, others not.
« Last Edit: June 09, 2017, 07:54:41 PM by NON »
Desktop: Win10 Pro 22H2 64bit / Core i5-7400 3.0GHz / 32GB RAM / Avast 23 Premium Beta(Icarus) / Comodo Firewall
Notebook: Win10 Pro 22H2 64bit / Core i5-3340M 2.7GHz / 12GB RAM / Avast 23 Free / Windows Firewall Control
Server: Win11 Pro 23H2 64bit / Core i3-4010U 1.7GHz / 12GB RAM / Avast One 23 Essential

Avast の設定について解説しています。よろしければご覧ください。