Freshly disclosed vulnerability CVE-2021-20090 exploited in the wild
blogs.juniper.net
blogs.juniper.net
The other key piece, is this bypass available from the internet generally or just from LAN side. That's a key difference, and not clear - I've found when they say remote unauthenticated attacker often these vulns are NOT available WAN side.
So you often end up with a better headline of wireless router vulnerable to LAN side authentication bypass.
I haven't looked at this one.
But CVE as a headline is not that useful -> get past overbroad statements -> you might get to a more useful one sentance headline (these articles sometimes require reading 300+ words to even get a sense of what risk actually is - it's the new style).
You're right that the risk is dropped significantly if the web ui isn't showing WAN side (though could still be an issue for businesses using the router for public wifi, or in shared residences, etc).
> As of August 5, we have identified some attack patterns that attempt to exploit this vulnerability in the wild coming from an IP address located in _Wuhan, Hubei province, China_.
It would be some next-level cyber trolling if the attacks were deploying some kind of a virus.
Oh the irony
I think this is one of those things where you hear about a type of car or something, then you start seeing it everywhere. They've always been there, but just never triggered those recognition circuits until they were primed to.
I've seen dozens of command injection bugs in router firmware, it's terrible how we never learn.