Virgin Media’s Super Hub gets hit by another big security flaw

Virgin Media’s Super Hub routers have once again been the victim of a major security flaw, although the good news is that the company has already patched this issue.

Recently, we’ve been hearing a lot about problems related to the firm’s newest Super Hub 3, but this latest vulnerability, discovered by Context Information Security, pertains to its predecessor.

Researchers found that the Super Hub 2 (and Super Hub 2AC – both made by Netgear) had a serious hole which could be exploited in a feature that allows the user to back up a custom configuration of the router.

The heart of the issue is that while configuration backups were encrypted, the private key for that encryption was the same across all routers in the UK.

As Context Information Security explains, that means an attacker who could access the admin interface of the Super Hub could download a configuration file, modify it to contain a backdoor enabling remote access, and then restore the file to the router.

And that would allow full remote access to the device, as well as the ability to monitor all traffic across the internet from connected pieces of hardware.

Prime target

Andy Monaghan, a principal security researcher at the company, commented: “The Super Hub represents the default home router offering from one of the UK’s largest ISPs and is therefore present in millions of UK households, making it a prime target for attackers.

“While ISP-provided routers like this are generally subject to more security testing than a typical off-the-shelf home router, our research shows that a determined attacker can find flaws such as this using inexpensive equipment.”

Context Information Security reported the issue to Virgin Media last October, and then worked with the company and Netgear to develop a patch which was rolled out last month.

So users are now protected against this flaw, thankfully, and hopefully security lessons will be learned for the future.

Back in April, the Super Hub 3 was reportedly found to be vulnerable to low-bandwidth denial-of-service attacks which can completely bog down the user’s internet connection.

Darren is a freelancer writing news and features for TechRadar (and occasionally T3) across a broad range of computing topics including CPUs, GPUs, various other hardware, VPNs, antivirus and more. He has written about tech for the best part of three decades, and writes books in his spare time (his debut novel - 'I Know What You Did Last Supper' - was published by Hachette UK in 2013).

Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
Lenovo | Thinkpad T14s Gen 6 Snapdragon
Windows 11’s latest patch declares war on BIOS updates for some Lenovo laptops, blocking them as a security risk in a bizarre turn of events
Tomodachi Life: Living the Dream screenshot showing a Mii smelling some fresh flowers.
Tomodachi Life: Living the Dream is a sequel to my favorite 3DS game, and I think it's already packing the charm that inZOI lacks
Google Pixel Watch 3 side dial and button
Google Gemini reportedly spotted on Wear OS – could a rollout be close at hand?
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Toni Collette in Hereditary
Everything leaving Netflix in April 2025 – from the scariest movie ever made to a beloved DreamWorks animation with 99% on Rotten Tomatoes