Vulnerability in wireless access points allowing traffic interception

A group of researchers from Tsinghua University (China) and George Mason University (USA) has revealed a vulnerability (CVE-2022-25667) in wireless access points that allows traffic interception (MITM) in wireless networks secured using WPA, WPA2, and WPA3 protocols. By manipulating ICMP packets with the 'redirect' flag, an attacker can redirect the victim's traffic within the wireless network through their system, which can be used to intercept and alter unencrypted sessions (for example, requests to sites without HTTPS).

The vulnerability is caused by a lack of proper filtering of spoofed ICMP messages with a modified sender address in network processors (NPU, Network Processing Unit), which handle low-level packet processing in the wireless network. Among other things, NPUs redirected spoofed ICMP packets with the 'redirect' flag without checking for spoofing, which can be used to modify the routing table parameters on the victim's side. The attack comes down to sending an ICMP packet on behalf of the access point with a 'redirect' flag containing spoofed data in the packet header. Due to the vulnerability, the message is redirected by the access point and processed by the victim's network stack, which believes the message was sent by the access point.

Vulnerability in wireless access points allowing traffic interception

Additionally, the researchers proposed a method for bypassing ICMP packet checks with the 'redirect' flag on the end-user side and modifying their routing table. To bypass filtering, the attacker first determines an active UDP port on the victim's side. Being on the same wireless network, the attacker can intercept traffic but cannot decrypt it, as they do not know the session key used when the victim connects to the access point. However, by sending the victim verification packets, the attacker, based on the analysis of incoming ICMP responses with the 'Destination Unreachable' flag, can identify the active UDP port. Next, the attacker creates an ICMP message with the 'redirect' flag and a forged UDP header that specifies the identified open UDP port. Processing this message results in corruption of the routing table in the victim's system and redirection of traffic with the potential for intercepting it in plaintext at the link layer.

Vulnerability in wireless access points allowing traffic interception

The presence of the problem has been confirmed in access points using chips from HiSilicon and Qualcomm. An examination of 55 different models of access points from 10 well-known manufacturers (Cisco, NetGear, Xiaomi, Mercury, 360, Huawei, TP-Link, H3C, Tenda, Ruijie) showed that they are all vulnerable and do not block spoofed ICMP packets. Furthermore, an analysis of 122 existing wireless networks revealed the possibility of an attack in 109 networks (89%).

Vulnerability in wireless access points allowing traffic interception

To exploit the vulnerabilities, an attacker must have legitimate access to the Wi-Fi network, meaning they must know the credentials for the wireless network (the vulnerabilities allow bypassing the traffic separation mechanisms in the WPA* protocols). Unlike traditional MITM attacks on wireless networks, by using ICMP packet spoofing techniques, the attacker can avoid deploying their own fake access point for traffic interception and instead use legitimate access points serving the network to redirect specially crafted ICMP packets to the victim.



Source: opennet.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster