I am new on these forums, but I hope someone can help me. Thank you.
I have a three-month Linksys router, it was working well until Avast started showing me the message: “Your device is vulnerable to attacks from within your network/Your device is not configured correctly/disable your device or update the firmware”
The firmware is up to date, the security is OK, Tech support has done everything to help me, they have checked everything and they say there is no problem with the router, that maybe it is something with my computer since there are no reports concerning Linksys and Avast; however Avast says everything is OK with my devices except for the router. Why is Avast showing me this message everyday?
I am ready to return the product (even when it works perfectly) and get another one for I am worried about this security issue :-
Could anyone help me, please?
This issue started happening like two months ago while running a scan then a Network scan. It showed me a list of my devices saying: "Your device is problem-free. Excellent! but the router was showing:“Your device is not configured correctly” then:
Service is vulnerable to attacks from within your network.
Catalogue ID CVE-2012-5958
Risks: Attackers can execute their own code on this device.
Attackers could completely control this device’s system.
Solution: Upgrade your device firmware, if possible.
Disable this service in this device’s settings.
Device is vulnerable to attacks.
Catalogue ID CVE-2017-14491
Risks: Attackers can abuse this vulnerability to disrupt normal functions of this device and make it unresponsive.
Attackers can execute their own code on this device.
Solution: Upgrade your device firmware, if possible.
Twice I called Linksys Tech Support and they checked my router’s security and everything was OK. The next day I run a scan and this time my router was problem-free too, but that changed the next week. Again the same process, the same messages from Avast and Support telling me that everything was OK and showing me a couple of very old false positive messages from this forum.
I handle my network and the router through the App on my phone.
Anyway, the last time I called and they told me what I wrote in the previous post. Saying that if I can handle the security and features through the App, I should be fine :-
But I do not feel secure anymore, I am worried everyday.
Thank you, hope you can help me or do you think I need another brand-router?
The CVE-2012-5958 and CVE-2017-14491 are not false positives. Recently the Wi-Fi Inspector component has added new signatures to detect more vulnerabilities.
Have you checked that you have the latest version of the router firmware? A lot of times router manufacturers do not release updates to solve vulnerabilities especially the older version models as you may find the latest version do not address the issues.
Thank you for your answer. I was hoping they were false…
Two days ago they told me I had the latest version, I have the App installed on my phone and it says that the firmware is up to date. However a couple of hours ago I visited the site to know what I need to do if I want to return the product and I found a new version on the site posted yesterday! I tried to download it to update the router manually but when the download finished a message saying “the disc is corrupt, can’t be mounted” appeared, I tried again like 4 times but it was the same. I did not want to waste time calling them, so I went to my router settings in order to do it automatically and it showed me “No updates available”!!
I even have the App configured to “automatic firmware update” and it is the same, it does not work. That does not make sense! >:(
I have been on this for weeks and they just telling me everything is OK. Right now I am looking for another router, I do not want this one anymore. Any suggestion for a new one?