Huawei checking claims of vulnerabilities in its routers

Security researchers found critical vulnerabilites in Huawei's AR18 and AR29 series routers
  • Michael Kan (IDG News Service)
  • — 02 August, 2012 02:50

Huawei Technologies said on Thursday it was verifying claims that its routers contained critical vulnerabilities, after security researchers disclosed alleged problems last weekend.

"We are aware of the media reports on security vulnerabilities in some small Huawei routers and are verifying these claims," Huawei said in an email. The company added it uses "rigorous security strategies and policies" to protect the networks of its customers, while following industry standards and best practices concerning security.

"Huawei has established a robust response system to address product security gaps and vulnerabilities," the company said. The company is also calling on industry to promptly report all product security risks so that the problems can be addressed and fixed, it said in its email.

The alleged security vulnerabilities were disclosed at the Defcon hackers conference this past Sunday by two security researchers. The vulnerabilities were found in the firmware of Huawei AR18 and AR29 series routers, which once exploited through the flaws, could be taken over via the Internet.

One of the researchers, Felix Lindner the head of security firm Recurity Labs, described the security of the Huawei devices he analyzed as "the worst ever", and said there were bound to be more security flaws with the products.

Huawei is one of the world's largest providers of networking equipment. Its AR18 series router is meant for small and home offices, while the AR29 series routers are designed for carrier networks or small enterprise branches, according to the company's website.

Comments are now closed.
CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Trend Micro Mobile Security

Comprehensive enterprise protection for mobile devices

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.