200 Vendors Impacted By DNS Poisoning Flaw

May 4, 2022

Researchers from security firm Nozomi Networks have uncovered a critical vulnerability in third-party code libraries used by hundreds of vendors.

The vulnerability is a DNS poisoning flaw. DNS poisoning allows attackers to replace the legitimate DNS lookup for a site with malicious IP addresses that can disguise as the real sites as they try to install malware.

In this case, the flaw allows attackers with access to the connection between an affected device and the internet to poison DNS requests used to translate domains to IP addresses.

The flaw is located in uClibc and uClibc fork uClibc-ng. The two libraries provide alternatives to the standard C library for embedded Linux, Nozom.

According to the researchers, 200 vendors incorporate at least one of the libraries into wares including Linksys WRT54G- Wireless-G Broadband Router, NetGear WG602 wireless router, and most Axis network cameras, embedded Gentoo, Buildroot, LEAF Bering uClibc, and Tuxscreen Linux Phone.

The sources for this piece include a story in ArsTechnica.

Top Stories

Related Articles

December 30, 2025 A fast-moving cyberattack has compromised more than 59,000 internet-facing Next.js servers in less than two days after more...

December 29, 2025 The U.S. National Institute of Standards and Technology (NIST) has warned that several of its Internet Time more...

December 29, 2025 A critical security flaw has been found in LangChain, one of the most widely used frameworks for more...

December 23, 2025 Editor's Notes: This is the first of two articles reflecting on the year but Yogi Schulz. Schulz' more...

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn