Post Now
Image

Oman stock exchange, one of the largest stock exchange in the middle east has quietly fixed a security issue in the router which could have given attackers unrestricted access to their networks.

Oman stock exchange, one of the largest stock exchange in the middle east has quietly fixed a security issue in the router which could have given attackers unrestricted access to their networks.Researchers discovered that the username and password of the core Huawei router of Oman stock exchange was  ‘admin’  for months, which is usually the default username and password of many routers unless the user changes it manually.This security issue in the router could have allowed hackers to gain administrator privileges and complete control over the network.The security issue was discovered by Victor Gevers, who is the chairman of  Netherland based non-profit GDI foundation focused on finding and reporting vulnerabilities.Researchers said that for past few months they were continuously trying to contact Oman authorities to warn about the issue despite several failed attempts.He found the router's IP address in the buried list of 33,000  telnet credentials which were leaked last year.

Read more on: Security Issue in Intel AMT allow Attackers to Gain Full Control of the System in Few Seconds
A major portion of leaked credentials are reportedly still working and can be used by botnet operators to mine cryptocurrency, shut down websites or can be used to spy on vulnerable networks.Gevers said that for past few months he has been trying to report each vulnerable device found in the list to its owners."Our advice was to block the telnet protocol on your firewall because this protocol is not safe to use anymore, If you need to mitigate this problem quickly we suggest you change this telnet password for a long and complex one. And then immediately apply a firewall rule to block the telnet service to only allow on their local network and start a replacement for this Huawei router as soon as possible," said Gevers.The vulnerable router has been fixed now, and it is still unclear exactly when was the fixed.