Asus router flaw leaves users' entire hard drives open to anyone on the Internet

Advertisement
By Jamshed Avari | Updated: 14 January 2014 16:58 IST
Convenience often comes at the cost of security, as demonstrated by Asus routers that come with a feature designed to allow users to access their hard drives' contents from anywhere in the world, but actually leave those drives open to anyone with an Internet connection. First reported by Sweden's IDG.se, the vulnerability has exposed how easy it is for users to unknowingly leave themselves open to malicious attacks, identity theft, piracy, and other security risks. The problem is the direct result of Asus consciously designing its default router configuration to favour convenience over security by not requiring a strong password.

The feature in question, called AiDisk, is designed to give users access to a hard drive plugged directly into a router's USB port. The feature is supported on a number of Asus router models, some of which have been on the market for over a year. All router manufacturers offer similar functionality on certain models.

Users who choose to plug a hard drive into their router might not be aware that Asus uses standard FTP (File Transfer Protocol) to make the drive function as a server, using your router's uniquely identifiable IP address. Such servers can be detected and accessed by anyone with an Internet connection, with very little effort. The routers also broadcast their model numbers by default, further inviting anyone who is familiar with the flaw. Visitors might have a casual interest in your server's contents, or they might have malicious intent-it's only a strong password that can keep them out. Unfortunately, in an effort to make FTP sharing completely transparent to users, Asus selected a default configuration option that does not require a password at all.

Advertisement

News site Thehackernews.com reports that Asus has acknowledged the problem and has committed to releasing a firmware patch for the affected models that will prompt users to configure a suitable password upon activating the feature. However it's impossible to estimate what percentage of affected users will install the patch or even be aware that it exists.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Edge 2026 With 6.3-Inch Display Goes Official
  2. Honor X7e With a 7,500mAh Battery Debuts Globally at This Price
  3. God of War Laufey Revealed at State of Play: Everything You Need to Know
  4. Lava Bold N2 5G Launched in India With 6,000mAh Battery, 6.75-Inch Display
  5. Samsung Galaxy Z Fold 8 Ultra Tipped to Get Battery, Charging Upgrades
  6. Realme P4R 5G India Launch Date, Design and Key Specifications Revealed
  7. Instagram May Soon Let Creators Group Reels Into Episodic 'Series'
  8.  Xiaomi 18, 18 Pro and 18 Pro Max Specifications Leaked Ahead of Debut
  9. Sony Bravia 7II 4K TVs With Cognitive Processor XR Debut in India
  1. Meta Reportedly Testing ‘Series’ Feature to Organise Instagram, Facebook Reels Into Episodic Collections
  2. Xiaomi 18 Tipped to Sport 6.4-Inch Display; Pro Models Said to Feature Dual 200-Megapixel Rear Cameras
  3. Realme P4R 5G India Launch Date Revealed Along With Design and Key Specifications
  4. Marvel's Wolverine Gets Visceral Gameplay Trailer at State of Play, Pre-Orders Now Live
  5. RTX Spark Laptops Said to Cost More Than Traditional AI PCs; Base Models Could Start at $1,799
  6. Lumio Introduces 55-Inch Variants of Vision 9 (2026) and Vision 7 (2026) Smart TVs in India: Price, Features
  7. Bitcoin Drops Below $67,000 as ETF Outflows, Institutional Selling Intensify
  8. Lava Bold N2 5G Launched in India With 6,000mAh Battery, 6.75-Inch Display: Price, Specifications
  9. WhatsApp Said to Be Developing On-Device Scam Detection Feature for Android
  10. Motorola Edge 2026 Launched With 6.3-Inch Display, MediaTek Dimensity 7450 SoC: Price, Specifications
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.