Asus router flaw leaves users' entire hard drives open to anyone on the Internet

Advertisement
By Jamshed Avari | Updated: 14 January 2014 16:58 IST
Asus router flaw leaves users' entire hard drives open to anyone on the Internet
Convenience often comes at the cost of security, as demonstrated by Asus routers that come with a feature designed to allow users to access their hard drives' contents from anywhere in the world, but actually leave those drives open to anyone with an Internet connection. First reported by Sweden's IDG.se, the vulnerability has exposed how easy it is for users to unknowingly leave themselves open to malicious attacks, identity theft, piracy, and other security risks. The problem is the direct result of Asus consciously designing its default router configuration to favour convenience over security by not requiring a strong password.

The feature in question, called AiDisk, is designed to give users access to a hard drive plugged directly into a router's USB port. The feature is supported on a number of Asus router models, some of which have been on the market for over a year. All router manufacturers offer similar functionality on certain models.

Users who choose to plug a hard drive into their router might not be aware that Asus uses standard FTP (File Transfer Protocol) to make the drive function as a server, using your router's uniquely identifiable IP address. Such servers can be detected and accessed by anyone with an Internet connection, with very little effort. The routers also broadcast their model numbers by default, further inviting anyone who is familiar with the flaw. Visitors might have a casual interest in your server's contents, or they might have malicious intent-it's only a strong password that can keep them out. Unfortunately, in an effort to make FTP sharing completely transparent to users, Asus selected a default configuration option that does not require a password at all.

News site Thehackernews.com reports that Asus has acknowledged the problem and has committed to releasing a firmware patch for the affected models that will prompt users to configure a suitable password upon activating the feature. However it's impossible to estimate what percentage of affected users will install the patch or even be aware that it exists.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo V60 With 50-Megapixel Telephoto Camera Debuts in India at This Price
  2. Samsung Galaxy S25 FE Price, Design, and Key Specifications Leaked
  3. Realme P4 Series Specifications Confirmed Ahead of Launch on August 20
  4. Check Deals on Smartphones During Flipkart Independence Day Sale 2025
  5. Vivo V60 Launching Today: Everything You Need to Know
  6. Apple Releases iOS 26 Beta 6 for iPhone With These New Features
  7. Google Pixel 10, 10 Pro, 10 Pro XL Renders Leaked: See Design, Colours
  8. Redmi Note 15 Pro Series Confirmed to Launch in China This Month
  1. Sony ULT Tower 9, ULT Tower 9AC, ULT Field 5, ULT Field 3 and ULTMIC1 Launched in India
  2. TecSox Omega TWS Earbuds With Up to 30 Hours Playback Time Launched in India
  3. OnePlus Partners Bhagwati Products to Assemble OnePlus Pad 3, OnePlus Pad Lite in India
  4. iQOO Z10 Lite 4G With Snapdragon 685 Chip, 50-Megapixel Camera Launched: Price, Specifications
  5. Zomato Gold Membership Renewal Price Drops to One Rupee for Some Customers
  6. Realme P4 Series Key Specifications Confirmed Ahead of Launch in India on August 20
  7. Sennheiser Accentum Open TWS Earphones Launched in India With IPX4 Rating, Up to 28 Hours of Battery Life
  8. Apple MacBook Model With A-Series Chip, Affordable Price Tag to Launch in Early 2026: Report
  9. Samsung Galaxy A07 Design, Colour Options, Key Features Leaked; Tipped to Get Six Android OS Upgrades
  10. Vu Glo QLED TV 2025 (Dolby Edition) Launched in India: Price, Specifications
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.