Asus router flaw leaves users' entire hard drives open to anyone on the Internet

Advertisement
By Jamshed Avari | Updated: 14 January 2014 16:58 IST
Asus router flaw leaves users' entire hard drives open to anyone on the Internet
Convenience often comes at the cost of security, as demonstrated by Asus routers that come with a feature designed to allow users to access their hard drives' contents from anywhere in the world, but actually leave those drives open to anyone with an Internet connection. First reported by Sweden's IDG.se, the vulnerability has exposed how easy it is for users to unknowingly leave themselves open to malicious attacks, identity theft, piracy, and other security risks. The problem is the direct result of Asus consciously designing its default router configuration to favour convenience over security by not requiring a strong password.

The feature in question, called AiDisk, is designed to give users access to a hard drive plugged directly into a router's USB port. The feature is supported on a number of Asus router models, some of which have been on the market for over a year. All router manufacturers offer similar functionality on certain models.

Users who choose to plug a hard drive into their router might not be aware that Asus uses standard FTP (File Transfer Protocol) to make the drive function as a server, using your router's uniquely identifiable IP address. Such servers can be detected and accessed by anyone with an Internet connection, with very little effort. The routers also broadcast their model numbers by default, further inviting anyone who is familiar with the flaw. Visitors might have a casual interest in your server's contents, or they might have malicious intent-it's only a strong password that can keep them out. Unfortunately, in an effort to make FTP sharing completely transparent to users, Asus selected a default configuration option that does not require a password at all.

News site Thehackernews.com reports that Asus has acknowledged the problem and has committed to releasing a firmware patch for the affected models that will prompt users to configure a suitable password upon activating the feature. However it's impossible to estimate what percentage of affected users will install the patch or even be aware that it exists.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo T4 Ultra to Launch in India on This Date
  2. OnePlus Ace 6 Series Tipped to Debut With Snapdragon Chips, IP68 Rating
  3. Samsung Teases 'Ultra' Foldable, May Debut Alongside Galaxy Z Fold 7
  4. Vivo Y19s Pro With 6,000mAh Battery, 50-Megapixel Main Camera Launched
  5. The Accountant 2 OTT Release Date: When and Whee to Watch it Online?
  6. iOS 26 to Arrive With These Upgrades for Messages, Apple Music and CarPlay
  7. Huawei Pura 80 Series to Launch on This Date
  1. Honor Magic V5 Allegedly Listed on Geekbench, Suggesting Key Specifications 
  2. Vivo T4 Ultra India Launch Date Set for June 11; Colour Options, Key Features Teased
  3. Google’s NotebookLM Adds Feature to Let Users Share Notebooks Publicly
  4. Huawei Pura 80 Series Launch Date Set for June 11; Key Camera Specifications Leaked
  5. The Witcher 4 Unreal Engine 5 Tech Demo Shows Stunning Open World, but CD Projekt Red Warns Its Not Gameplay
  6. Adobe Photoshop for Android App With Firefly-Powered Generative Fill Released in Beta
  7. The Fire And The Moth Now Streaming on Amazon Prime Video
  8. The Accountant 2 OTT Release Date: When and Whee to Watch it Online?
  9. Google Pixel 10 Series to Reportedly Offer Gimbal-Like Video Stabilisation
  10. iOS 26 to Bring Message Translation, Animated Lock Screen Album Artwork and Revamped CarPlay UI: Report
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.