Huawei plays down router security fears

By Ken Presti, on Aug 3, 2012 8:04 AM
Filed under Communications

Looks to verify allegations.

Chinese networking vendor Huawei has launched an investigation into reports that at least two of its routers have major security vulnerabilities.

The flaws are reported to make the devices subject to takeover through either a heap overflow or a stack overflow in the firmware of the company's AR18 and AR29 series routers.

The purported vulnerabilities were discussed Sunday at the Defcon conference in Las Vegas during a presentation by Felix Lindner, the head of security firm Recurity Labs and his colleague, security consultant Gregor Kopf.

According to both men, there are literally thousands of calls within the firmware to a function called "sprintf," which is known to have security challenges.

In response, Huawei issued a statement indicating that the company is in the process of verifying the claims.

"Huawei adopts rigorous security strategies and policies to protect the network security of our customers, and abides by industry standards and best practices in security risk and incident management," read the statement.

"Huawei has established a robust response system to address product security gaps and vulnerabilities, working with our customers to immediately develop contingency plans for all identified security risks, and to resolve any incidents in the shortest possible time."

The statement also calls upon the technology industry to promptly report all product security risks so that the vendor's CERT team can address whatever security issues may emerge.

Lindner and Kopf said based on the relative quality of the Huawei code, it's likely that additional issues will be found in the near future.

Huawei's AR18 router series router is specifically aimed at the SOHO market. The AR29 router series is part of a new product portfolio aimed at enterprise customers.

 
Follow us on Facebook and Twitter
 

Copyright © 2011 United Business Media LLC. All rights reserved.

Huawei plays down router security fears
Tags
 
 
 
 
 
Top Stories
In pictures: HTC One vs Samsung Galaxy S4
Two Android titans battle it out.
 
Dell's fiscal silver lining
Remaking itself into an enterprise company.
 
In pictures: Google I/O 2013
Evolution not revolution.
 
Sign up to receive CRN email bulletins
   FOLLOW US...
Latest Comments
Polls
Is your business doing as well now as it was at this time last year?


   |   View results
Yes
  31%
 
No
  53%
 
The same
  15%
TOTAL VOTES: 346

Vote now
CRN Magazine

Issue: 315 | May 2013

CRN Magazine looks in-depth at the emerging issues and developments for the channel, and provides insight, analysis and strategic information to help resellers better run their businesses.