Skip to content

Commit aec47fe

Browse files
committed
Add update recommendation for end users noting that the built-in update functionality may not work
1 parent d380d0e commit aec47fe

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

README.md

+3-1
Original file line numberDiff line numberDiff line change
@@ -121,7 +121,9 @@ If an attacker specifies the *OpCode* value of *NET_CMD_ID_MANU_CMD*, the preced
121121
122122
Recommendations
123123
---------------
124-
Remove the remote command execution functionality from this service. Even if it were guarded with strong authentication, broadcasting a password to the entire local network isn't really something to be desired. If command execution is truly desired it should be provided via SSH or similar secure mechanism.
124+
*End Users*: Update firmare to revision 3.0.0.4.376.3754 or newer. It's important to note that the router's "Check for Update" functionality may not work properly. Manually check the version of the firmware you're running and, if older, download/install the new firmware.
125+
126+
*ASUS/Merlin*: Remove the remote command execution functionality from this service. Even if it were guarded with strong authentication, broadcasting a password to the entire local network isn't really something to be desired. If command execution is truly desired it should be provided via SSH or similar secure mechanism.
125127
126128
Workaround
127129
----------

0 commit comments

Comments
 (0)