Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

Unpatched Vulnerabilities Expose Yifan Industrial Routers to Attacks

Industrial routers made by Chinese company Yifan are affected by several critical vulnerabilities that can expose organizations to attacks. 

Industrial routers made by Chinese company Yifan are affected by several critical vulnerabilities that can expose organizations to attacks, Cisco’s Talos threat intelligence and research group reported on Wednesday.

The vendor was notified in late June and given more than 90 days to release patches. However, no fixes appear to have been released and Cisco has made public the technical details in accordance with its vulnerability disclosure policy. 

A Talos researcher discovered over a dozen vulnerabilities in Yifan’s YF325 cellular router. According to the vendor, the device has been deployed in various fields, including self-service terminals, intelligent transportation, industrial automation, smart grid, water supply, finance, and point-of-sale systems. 

A majority of the flaws found in the router have been assigned ‘critical severity’ ratings and the remaining have been classified as ‘high severity’. 

Talos said the most serious of the security holes can be exploited to execute an arbitrary shell on the targeted router (CVE-2023-32632), change the admin credentials of the device and obtain root access (CVE-2023-24479), and leverage leftover debug credentials to access the device with admin privileges (CVE-2023-32645).

The remaining weaknesses can be exploited for arbitrary code/command execution and denial-of-service (DoS) attacks.

All vulnerabilities can be exploited by sending specially crafted network requests to the targeted device.

SecurityWeek has reached out to Yifan for comment and will update this article if the company responds. 

Learn More at SecurityWeek’s ICS Cyber Security Conference
The leading global conference series for Operations, Control Systems and OT/IT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.
ICS Cybersecurity Conference
October 23-26, 2023 | Atlanta
www.icscybersecurityconference.com

Related: Dozens of RCE Vulnerabilities Impact Milesight Industrial Router

Related: InHand Industrial Router Vulnerabilities Expose Internal OT Networks to Attacks

Advertisement. Scroll to continue reading.

Related: 10 Vulnerabilities Found in Widely Used Robustel Industrial Routers

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Mike Dube has joined cloud security company Aqua Security as CRO.

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Vulnerabilities

Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.

IoT Security

A vulnerability affecting Dahua cameras and video recorders can be exploited by threat actors to modify a device’s system time.