ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Exploits

Critical Vulnerabilities in IoT Routers Threaten Industries, Warns Forescout Analysts

Paul by Paul
November 14, 2023
in Exploits
Reading Time: 2 mins read
Unveiling imminent threats: Forescout's analysts expose critical vulnerabilities in IoT routers, risking industries and urging immediate action.
Share on FacebookShare on Twitter

On Dec. 7 at Black Hat Europe, analysts from Forescout will reveal the bugs — including one of 9.6 “Critical” severity on the CVSS scale, and nine “High” severity — affecting a brand of operational technology (OT)/Internet of Things (IoT) routers especially common in the medical and manufacturing sectors.

You might also like

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

Critical Vulnerabilities Exposed in Ruijie Networks Cloud Platform

Picture OT/IoT routers as the bridges connecting the broader Internet to internal networks through 3G and 4G cellular networks. They’re commonly spotted in crucial areas such as transportation, government, and water treatment. If these devices are compromised, it opens the door to serious consequences like lateral movement within networks, deploying malware, engaging in espionage, disrupting services, and more.

Let’s delve into the vulnerabilities. Seven of the fresh discoveries are nestled within the internal components of these routers, while fourteen stem from open-source elements, including a captive portal for Wi-Fi networks and an XML processing library. The issues span a spectrum of risks, from cross-site scripting (XSS) to denial of service (DoS), remote code execution (RCE), unauthorized access, and authentication bypass.

Breaking it down, these bugs can be sorted into two main groups, as explained by Daniel dos Santos, the head of security research at Forescout. They’re either design flaws like hardcoded credentials and SSL certificates or relate to how the device handles potentially harmful inputs, which could lead to injecting malicious code or crashing the device.

The implications of an attack on these devices are profound. Attackers can sidestep traditional industrial security measures and directly target the most critical devices in a facility. Dos Santos walks us through the typical path of an attack: starting on the IT network, making lateral moves, breaching the gap with OT through an engineering workstation or SCADA system, and ultimately gaining access to IoT devices.

What sets these routers apart is their direct connection of potentially critical devices to the Internet without the need for typical IT-OT lateral movement. This poses a unique risk for devices in critical infrastructure like pipelines or substations.

Now, onto the numbers. Forescout’s researchers, armed with regular scans, discovered over 80,000 vulnerable OT/IoT devices unprotected on the open web, with a significant chunk located in the US. Alarmingly, 22,000 of these devices use default SSL certificates, making them susceptible to easy man-in-the-middle attacks. Adding to the concern, less than 10% of these devices are fortified against publicly known vulnerabilities.

Digging deeper, for those with management interfaces, 80% are at the end of their life cycle, rendering them unpatchable. This predicament is prevalent in industrial settings due to the complexities and risks associated with updating or replacing specific critical software and machinery operating 24/7.

Dos Santos emphasizes a concerning habit within the industry: treating devices as legacy just because they belong to the OT world. This perception delays necessary upgrades, creating a vulnerability in the OT perimeter. He concludes, “We don’t need to replace it right now, but that’s definitely problematic, and this is one area of the OT perimeter that could be helped in upgrading devices.”

Tags: SCADA
Previous Post

Boeing Faces Cybersecurity Crisis: Lockbit Ransomware Attack Exposes Sensitive Data Amid Citrix Vulnerability Concerns

Next Post

Chinese Scammers Cloning Websites for Massive Gambling Scam in Asia-Pacific Region

Paul

Paul

Editor and chief at ZeroSecurity. Expertise includes programming, malware analysis, and penetration testing. If you would like to write for ZeroSecurity, please click "Contact us" at the bottom of the page.

Recommended For You

Photo of the CISCO logo and text saying "You have been hacked!"

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

March 6, 2026
What is DoubleClickJacking?

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

Critical Vulnerabilities Exposed in Ruijie Networks Cloud Platform

December 25, 2024

Vulnerability (CVE-2024-54143 ) Discovered in OpenWrt’s Firmware Upgrade System

December 13, 2024

Cybercriminals Unleash Advanced Phishing-as-a-Service Toolkit Targeting Microsoft 365 Users

November 29, 2024

Major Security Vulnerability Uncovered in qBittorrent Client

November 1, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.