Vulnerabilities Allowing Image Replacement and Code Execution on ASU Servers in the OpenWrt Project
Critical vulnerabilities (CVE-2024-54143) have been identified in the ASU (Attended SysUpgrade) toolkit developed by the OpenWrt project, which could compromise build artifacts distributed via the sysupgrade.openwrt.org service or third-party ASU servers, enabling attackers to install modified firmware images on user systems that use the "attended upgrade" mode through the web interface selector.openwrt.org or the command-line attended.sysupgrade tool. An attacker needs only to send […]
