RW-Fuzzer: A Fuzzing Method for Vulnerability Mining on Router Web Interface

Longjuan Wang,Chunjie Cao,Jun Ye,Wenjie Zhong
DOI: https://doi.org/10.1155/2022/5311295
2022-04-25
Wireless Communications and Mobile Computing
Abstract:As the main routing device of the network, most routers can be set up and managed through their web enabled admin portal. This paper proposes a new method for router admin portal vulnerability mining fuzzing test (RW-fuzzer: Router Web fuzzer). The mutation samples that generated by Boofuzz are used to construct the test sample set for fuzzy testing. The constructed mutation test cases are more suitable for the attack load or critical value of the router’s Web interface. They can cause unexpected errors for the devices more easily, which achieves the goal of discover potential vulnerabilities, and the practicality is excellent. Based on the proposed RW-fuzzer method, this work conducted fuzzing tests on 4 widely sold router models from manufacturers. Four nday vulnerabilities and one 0day vulnerability have been found. Experiment results show that the proposed RW-fuzzer method is effective.
computer science, information systems,telecommunications,engineering, electrical & electronic
What problem does this paper attempt to address?