Asus router flaw leaves users' entire hard drives open to anyone on the Internet

Advertisement
By Jamshed Avari | Updated: 14 January 2014 16:58 IST
Convenience often comes at the cost of security, as demonstrated by Asus routers that come with a feature designed to allow users to access their hard drives' contents from anywhere in the world, but actually leave those drives open to anyone with an Internet connection. First reported by Sweden's IDG.se, the vulnerability has exposed how easy it is for users to unknowingly leave themselves open to malicious attacks, identity theft, piracy, and other security risks. The problem is the direct result of Asus consciously designing its default router configuration to favour convenience over security by not requiring a strong password.

The feature in question, called AiDisk, is designed to give users access to a hard drive plugged directly into a router's USB port. The feature is supported on a number of Asus router models, some of which have been on the market for over a year. All router manufacturers offer similar functionality on certain models.

Users who choose to plug a hard drive into their router might not be aware that Asus uses standard FTP (File Transfer Protocol) to make the drive function as a server, using your router's uniquely identifiable IP address. Such servers can be detected and accessed by anyone with an Internet connection, with very little effort. The routers also broadcast their model numbers by default, further inviting anyone who is familiar with the flaw. Visitors might have a casual interest in your server's contents, or they might have malicious intent-it's only a strong password that can keep them out. Unfortunately, in an effort to make FTP sharing completely transparent to users, Asus selected a default configuration option that does not require a password at all.

News site Thehackernews.com reports that Asus has acknowledged the problem and has committed to releasing a firmware patch for the affected models that will prompt users to configure a suitable password upon activating the feature. However it's impossible to estimate what percentage of affected users will install the patch or even be aware that it exists.

 

For details of the latest launches and news from Samsung, Xiaomi, Realme, OnePlus, Oppo and other companies at the Mobile World Congress in Barcelona, visit our MWC 2025 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. iPhone 17e vs iPhone 17: Price in India, Features, Specifications Compared
  2. Tecno Pop X Launched in India With 5,000mAh Battery, IP64 Rating: See Price
  3. MacBook Pro (2026) With M5 Pro, M5 Max Chips Launched in India: See Price
  4. Tecno Megapad 2, Tecno Watch GT 1S and Tecno FreeHear 2 Debut at MWC 2026
  1. Vivo V70 FE Colour Options, Key Specifications Revealed Ahead of March 9 Launch
  2. Apple MacBook Neo Reportedly Listed on Regulatory Site Hours Before Anticipated Launch
  3. Tecno Pop X Launched in India With 5,000mAh Battery, IP64 Rating: Price, Specifications
  4. Tecno Megapad 2, Tecno Watch GT 1S and Tecno FreeHear 2 Unveiled at MWC 2026: Availability, Features
  5. Mike & Nick & Nick & Alice OTT Release Date: Know When and Where to Watch it Online
  6. MediaTek Showcases AI Glasses at MWC 2026; Demonstrates Emergency Satellite Alerts With Starlink
  7. Devagudi Now Streaming Online: Where to Watch Intense Drama Online?
  8. Jab Khuli Kitaab OTT Release Date: When and Where to Watch Pankaj Kapur and Dimple Kapadia Starrer Romantic Drama Online?
  9. Apple Introduces M5 Pro, M5 Max Chips With New Fusion Architecture on 2026 MacBook Pro Models
  10. Apple Studio Display, Studio Display XDR With 27-Inch 5K Displays Launched in India: Price, Features
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.