Asus router flaw leaves users' entire hard drives open to anyone on the Internet

Advertisement
By Jamshed Avari | Updated: 14 January 2014 16:58 IST
Convenience often comes at the cost of security, as demonstrated by Asus routers that come with a feature designed to allow users to access their hard drives' contents from anywhere in the world, but actually leave those drives open to anyone with an Internet connection. First reported by Sweden's IDG.se, the vulnerability has exposed how easy it is for users to unknowingly leave themselves open to malicious attacks, identity theft, piracy, and other security risks. The problem is the direct result of Asus consciously designing its default router configuration to favour convenience over security by not requiring a strong password.

The feature in question, called AiDisk, is designed to give users access to a hard drive plugged directly into a router's USB port. The feature is supported on a number of Asus router models, some of which have been on the market for over a year. All router manufacturers offer similar functionality on certain models.

Users who choose to plug a hard drive into their router might not be aware that Asus uses standard FTP (File Transfer Protocol) to make the drive function as a server, using your router's uniquely identifiable IP address. Such servers can be detected and accessed by anyone with an Internet connection, with very little effort. The routers also broadcast their model numbers by default, further inviting anyone who is familiar with the flaw. Visitors might have a casual interest in your server's contents, or they might have malicious intent-it's only a strong password that can keep them out. Unfortunately, in an effort to make FTP sharing completely transparent to users, Asus selected a default configuration option that does not require a password at all.

News site Thehackernews.com reports that Asus has acknowledged the problem and has committed to releasing a firmware patch for the affected models that will prompt users to configure a suitable password upon activating the feature. However it's impossible to estimate what percentage of affected users will install the patch or even be aware that it exists.

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Amazon Great Republic Day Sale 2026 to Start Soon With These Bank Offers
  2. Top OTT Releases of the Week: De De Pyaar De 2, Akhanda 2, Mask, and More
  3. Redmi Note 15 5G Goes on Sale in India: See Price, Launch Offers
  4. OnePlus Turbo 6, Turbo 6V Launched With These Snapdragon Chipsets
  5. Oppo Pad 5 With a 10,050mAh Battery Launched in India at This Price Tag
  6. Poco M8 Pro 5G Launched Globally With 6,500mAh Battery at This Price
  7. Realme Neo 8 Confirmed to Launch in China Next Week
  8. Google Could Add AirDrop Compatibility to These Pixel Models
  9. Vivo X200T Tipped to Launch Soon With Dimensity 9400+ SoC, 6,200mAh Battery
  10. What is SBI Statement Password: How to Open Statement PDF, More
  1. Oppo Find N7 to Feature Wider Book-Style Display as Find N6 China Launch Nears: Report
  2. Tecno Spark Go 3 India Launch Date, Design Revealed; Will Go on Sale via Amazon
  3. Qualcomm Suggests Its Chips Will Power Most Galaxy S26 Models; Samsung May Produce 2nm Snapdragon 8 Elite Gen 5: Reports
  4. Google Brings Gmail to the Gemini Era With AI Overviews Integration and a New Inbox
  5. Amazon Great Republic Day Sale 2026 to Start Soon; Discounts, Bank Offers Teased
  6. YouTube Updates Search Filters With New Shorts Option and Simplified Sorting
  7. Realme Neo 8 China Launch Date Announced; Company Teases Display Details
  8. iOS 26 Adoption Rate Notably Lower Than Previous Versions Months After Launch: Report
  9. Redmi Note 15 5G Goes on Sale in India for the First Time Today: Price, Specifications, Sale Offers
  10. Samsung Galaxy M17e 5G Reportedly Listed on Google Play Console; Could Arrive With Familiar Specifications
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.