Found this article interesting? Longenecker explains that all it takes is a simple cross site request forgery (CSRF) attack, as the application does not verify whether the command to reboot or reset the modem actually comes from the modem's UI. The first issue is quite basic: the user interface for the modem has absolutely no authentication set up. He writes troubleshooting content and is the General Manager of Lifewire. A restart/reboot is a single step that involves both shutting down and then powering on something. The bad news is that it's not that simple in practice. Google Podcasts | "Did you know that a web browser doesn't really care whether an 'image' file is really an image? From there, they can have a little fun according to Longenecker's blog post: "With access to a local network, it is a trivial matter to reboot the modem serving that network, causing a denial of service while the modem reboots.

Well the least the attackers could do if they decide to reboot it, is to apply the patch first. The good news is that these flaws are easily patchable in theory. We have updated the headline and article accordingly. We are in the process of working with our Service Provider customers to make this release available to subscribers. There is no risk of access to any user data, and we are unaware of any exploits.

While they wait for a patch, those familiar with IP tables could add a rule that limits access to the modem's LAN interface to only one local IP address and which disallows web browsing from that address.

The reason it's important to know the difference between restart and reset is that they do two very different things, despite sounding like the same word.

If you can't find the button, search online for the router model you're using. I love this: hackers can access these boxes, but can we mere OWNERS install the [STILL NOT EXISTENT] firmware? To use the factory reset method, locate the same button of the pinhole on the back of your router. To reset a device is to put it back in the same state it was in when it was first purchased, often called a restore or factory reset (also a hard reset).

Cable modems are not consumer-upgradable, which means even in the event Arris were to develop a fix, customers would need to wait for their ISPs to push the update to them.

So basically, nothing sold to consumers has ever been secure, nor will EVER be made secure, because corporate profits.

The 135 million number is not an accurate representation of the units impacted.". He works as Contributing Editor for Graham Cluley Security News and Associate Editor for Tripwire's "The State of Security" blog. worms have also patched holes (including the Linux Ramen worm – which as I recall shouldn't have compromised any system since fixes for the software were available). At this time, Arris has still not created a firmware update… even though Longenecker notified the company of the issues back in January. Up to 13.5 million Arris modems are at risk of being knocked offline for between three and 30 minutes, because of an easily patchable vulnerability. Causing a modem to reboot is as simple as including an 'image' in any other webpage you might happen to open… Of course it's not a real image, but the web browser doesn't know that until it requests the file from the modem IP address – which of course causes the modem to reboot.". The reason it's important to know the difference between restart and reset is that they do two very different things, despite sounding like the same word. The good news is that these flaws are easily patchable in theory. Unfortunately, if an attacker were looking to be an all-out nuisance, that same web user interface provides them with the ability to factory reset the modem. All Arris needs to do is create a firmware update that does two things: first, requires authentication before someone can use the UI to reboot or reset the modem; and second, verifies that a request originates from the application and not from an external source. This potentially leaves millions of Arris customers out of luck for an indefinite period of time. So for the past few days my Arris modem has been restarting constantly, Dropping my internet connection, it has become very frustrating as I cant do anything on the internet for more than maybe an hour or so in the evening, Between about 10 am to 6 pm it is fine but around 6 pm it starts doing this

This includes anything loaded into memory, like any videos you're playing, websites you have open, documents you're editing, etc.

