Unpatched DNS-Poisoning Bug Affects Millions of Devices, Stumps Researchers

After months of work by industrial management methods (ICS) cybersecurity groups, a repair for a widespread Domain Name System (DNS) poisoning bug nonetheless hasn’t been discovered. Now they’re asking for assist from the broader cybersecurity neighborhood.
A weblog submit from a staff of ICS analysts at Nozomi Networks defined the flaw exists in all variations of the extensively used C customary library for Internet of Things (IoT) gear referred to as uClibc, in addition to uClibc-ng, which is a particular model for OpenWRT, a “common OS for routers deployed throughout various critical infrastructure sectors.”
As such, the bug exists in large name-brand merchandise from Linksys, Netgear, and Axis, and in Linux distributions reminiscent of Embedded Gentoo. Since January, the vulnerability has been disclosed to 200+ distributors, and it probably impacts hundreds of thousands of put in units.
Additional specifics on the units affected aren’t being offered publicly as a result of the DNS bug continues to be unpatched, however Nozomi offered particulars on the bug and its exploitability after the library’s maintainer was unable to develop a repair — in hopes of soliciting assist from the neighborhood.
The affect of an exploit could possibly be vital: “Because of its relevance, DNS can be a valuable target for attackers,” the analysis staff defined within the submit. “In a DNS poisoning attack, an attacker is able to deceive a DNS client into accepting a forged response, thus inducing a certain program into performing network communications with an arbitrarily defined endpoint, and not the legitimate one.”
Once profitable, the attacker may alter or intercept community site visitors to compromise linked units, the staff mentioned.
“A DNS poisoning attack enables subsequent Man-in-the-Middle attacks because the attacker, by poisoning DNS records, is capable of rerouting network communications to a server under their control.” the Nozomi team warned. “The attacker could then steal and/or manipulate information transmitted by users, and perform other attacks against those devices to completely compromise them.”
Source link


![The OpenWrt One system [LWN.net] The OpenWrt One system [LWN.net]](https://openwrtrouters.net/wp-content/uploads/2026/09/openwrt-one-sm-250x220.png)