National Research Center for Applied Cybersecurity ATHENE: Severe Vulnerabilities Discovered in Software to Protect Internet Routing
A research team from the National Research Center for Applied Cybersecurity ATHENE led by Prof. Dr. Haya Schulmann has uncovered 18 vulnerabilities in crucial software components of Resource Public Key Infrastructure (RPKI). RPKI is an Internet standard meant to protect Internet traffic from being hijacked by hackers. By now, all affected vendors provided patches for their products. The vulnerabilities could have had devastating consequences: Internet hijacks have already been exploited, e.g., for phishing passwords and other sensitive information, tricking certificate authorities into issuing fraudulent Web certificates, stealing cryptocurrency, distributing malware, and poisoning caches of DNS servers.

Frankfurt and Darmstadt, April 2024
The ATHENE team consisting of Prof. Dr. Haya Schulmann and Niklas Vogel, both from Goethe University of Frankfurt, Donika Mirdita from TU Darmstadt, and Prof. Dr. Michael Waidner from TU Darmstadt and Fraunhofer SIT uncovered and disclosed 18 vulnerabilities. The National Vulnerability Database (NVD), operated by the US National Institute of Standards and Technology (NIST), assigned five Common Vulnerabilities and Exposures (CVE) entries to these vulnerabilities, some critical with a score of 9.3 out of 10. The team used a testing tool, CURE, which they developed specifically for this project and which ATHENE makes available free of charge to all developers of RPKI software. The researchers found vulnerabilities in all popular implementations of the validator component of RPKI. They range between crashes, violation of standard behavior, and even severe bugs that allow a network adversary to completely take over an RPKI certificate hierarchy in order to inject its own trust anchor – effectively being able to forge authentic and valid yet bogus routing information (i.e., BGP announcements). It is unknown whether any of the vulnerabilities were already exploited by hackers in the wild.
RPKI is a relatively new standard. Today, about 50% of the Internet’s network prefixes are covered by RPKI certificates, and 37.8% of all Internet domains validate RPKI certificates. In particular, many large providers and operators support RPKI, e.g., Amazon Web Services, Cogent, Deutsche Telekom, Level 3, and Zayo.
The research work was carried out in the ATHENE research area Analytic Based Cybersecurity (ABC) (more information at https://abc.athene-center.de/en/ ) and appeared at the 2024 Network and Distributed System Security (NDSS) Symposium in San Diego, California, USA. The research paper can be downloaded from https://www.ndss-symposium.org/ndss-paper/the-cure-to-vulnerabilities-in-rpki-validation/. The testing tool CURE developed and used by the researchers to uncover the vulnerabilities can be downloaded from https://github.com/rp-cure/rp-cure.
The National Research Center for Applied Cybersecurity ATHENE is a research center of the Fraunhofer Society that brings together the Fraunhofer Institutes for Secure Information Technology (SIT) and for Computer Graphics Research (IGD), Technische Universität Darmstadt, Goethe-Universität Frankfurt am Main, and Darmstadt University of Applied Sciences. With more than 600 scientists, ATHENE is Europe's most prominent cybersecurity research center and Germany’s leading scientific research institution in this domain. ATHENE is supported by the German Federal Ministry of Education and Research (BMBF) and the Hessian Ministry for Higher Education, Research, Science and the Arts (HMWK). Further information about ATHENE can be found at https://www.athene-center.de/en/.
Press Contact: Mrs. Cornelia Reitz, cornelia.reitz@athene-center.de
Subscribe to releases from news aktuell GmbH
Subscribe to all the latest releases from news aktuell GmbH by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from news aktuell GmbH
Valle Venia presents Sandgrain in Space LPS feat. Lara5.12.2025 10:15:00 CET | Press release
A Cosmic Song on Self Creation, Inner Rebirth, and the Quiet Power of Becoming
The German advertising market is facing another year of stagnation in 20263.12.2025 12:56:58 CET | Press release
The JOM Group’s latest advertising market forecast shows that the continuing economic uncertainty means that companies only have limited growth potential for increasing advertising investments.
Change in leadership at Visable: Patrick Sostmann to take over from Peter F. Schmid as CEO of Visable Group on January 1, 20262.12.2025 09:35:00 CET | Press release
(Hamburg, Germany) – After more than 13 years at the helm of Visable, Peter F. Schmid will hand over leadership of the Visable Group to Patrick Sostmann, who has been CCO at Visable since June 2025, on January 1, 2026. Visable operates the B2B marketplaces wer liefert was (wlw) and europages. The handover at the top underscores the company's continuous development and its close partnership with Alibaba.com. Sostmann will continue to drive forward the strategy based on AI investments and user orientation, thereby expanding the B2B marketplaces into European market leaders in digital B2B business. Over the past 13 years, Peter F. Schmid has transformed the long-established German business directory wer liefert was (wlw) into the internationally active digital company Visable, which now operates the two leading B2B marketplaces europages and wer liefert was (wlw). The last key milestone was Alibaba.com becoming majority shareholder in 2023. With these steps, Peter F. Schmid has set the co
PLAN-B NET ZERO sets new standards in the energy market with Neo Energy25.11.2025 13:34:49 CET | Press release
The Swiss green tech scale-up is positioning itself as a pioneer, transforming sustainable energy from a commodity into a digital lifestyle experience
Hessian Minister President Boris Rhein presents the Broermann Medical Innovation Award18.11.2025 16:00:00 CET | Press release
Dr. Carl June and Dr. Michel Sadelain honored for groundbreaking CAR-T cell research in cancer therapy One of the world’s most highly endowed medical prizes, with €1 million in prize money, awarded for the first time Titia große Broermann: “With the Broermann Medical Innovation Award, we want to make outstanding medical achievements visible – and honor those who, with courage, vision, and humanity, are shaping the medicine of tomorrow.”
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom