Belkin CherryBlossom Advisory

Advisory Date:  6/21/17
 
Overview

Belkin is aware of the CherryBlossom project that was recently released by WikiLeaks’ Vault 7 publication.  Based on the WikiLeaks report customized firmware was created for certain older Belkin routers without our knowledge or consent for the purposes of monitoring, controlling, and manipulating internet traffic of a "targeted" user. 
 
This customized firmware can be loaded onto a router using one of the following methods:
  • physical access to the router
  • proximity access to the router via Wi-Fi
  • intercepting the device in transit to be delivered to a user
 
Solution

If users believe their router firmware may have been compromised, Belkin recommends that users download the latest available firmware from https://www.belkin.com/support and update your router. 
 
After the update, please perform a factory reset to ensure no remnants of the compromise remain.  Instructions on how to do a factory reset can be found here.  If users are not able to perform a firmware update or receive an error message during the update, please contact customer support for further instructions. 
 
We would also like to recommend the following changes after the factory reset is complete to further secure the router:
  • Set a strong admin password (one that includes capital letters, numbers, special characters, and a password length of at least 8 characters)
  • Disable Guest Access if it is not in use
  • Disable router features (like WPS and UPnP®) if they are not being used


    Potentially Affected Products
Belkin F5D8231-4
Belkin F5D7230-4
Belkin F5D8230-4
Additional Support Questions?
Search Again