National Research Center for Applied Cybersecurity ATHENE: Severe Vulnerabilities Discovered in Software to Protect Internet Routing
12.4.2024 08:49:14 CEST | news aktuell GmbH | Press release
A research team from the National Research Center for Applied Cybersecurity ATHENE led by Prof. Dr. Haya Schulmann has uncovered 18 vulnerabilities in crucial software components of Resource Public Key Infrastructure (RPKI). RPKI is an Internet standard meant to protect Internet traffic from being hijacked by hackers. By now, all affected vendors provided patches for their products. The vulnerabilities could have had devastating consequences: Internet hijacks have already been exploited, e.g., for phishing passwords and other sensitive information, tricking certificate authorities into issuing fraudulent Web certificates, stealing cryptocurrency, distributing malware, and poisoning caches of DNS servers.

Frankfurt and Darmstadt, April 2024
The ATHENE team consisting of Prof. Dr. Haya Schulmann and Niklas Vogel, both from Goethe University of Frankfurt, Donika Mirdita from TU Darmstadt, and Prof. Dr. Michael Waidner from TU Darmstadt and Fraunhofer SIT uncovered and disclosed 18 vulnerabilities. The National Vulnerability Database (NVD), operated by the US National Institute of Standards and Technology (NIST), assigned five Common Vulnerabilities and Exposures (CVE) entries to these vulnerabilities, some critical with a score of 9.3 out of 10. The team used a testing tool, CURE, which they developed specifically for this project and which ATHENE makes available free of charge to all developers of RPKI software. The researchers found vulnerabilities in all popular implementations of the validator component of RPKI. They range between crashes, violation of standard behavior, and even severe bugs that allow a network adversary to completely take over an RPKI certificate hierarchy in order to inject its own trust anchor – effectively being able to forge authentic and valid yet bogus routing information (i.e., BGP announcements). It is unknown whether any of the vulnerabilities were already exploited by hackers in the wild.
RPKI is a relatively new standard. Today, about 50% of the Internet’s network prefixes are covered by RPKI certificates, and 37.8% of all Internet domains validate RPKI certificates. In particular, many large providers and operators support RPKI, e.g., Amazon Web Services, Cogent, Deutsche Telekom, Level 3, and Zayo.
The research work was carried out in the ATHENE research area Analytic Based Cybersecurity (ABC) (more information at https://abc.athene-center.de/en/ ) and appeared at the 2024 Network and Distributed System Security (NDSS) Symposium in San Diego, California, USA. The research paper can be downloaded from https://www.ndss-symposium.org/ndss-paper/the-cure-to-vulnerabilities-in-rpki-validation/. The testing tool CURE developed and used by the researchers to uncover the vulnerabilities can be downloaded from https://github.com/rp-cure/rp-cure.
The National Research Center for Applied Cybersecurity ATHENE is a research center of the Fraunhofer Society that brings together the Fraunhofer Institutes for Secure Information Technology (SIT) and for Computer Graphics Research (IGD), Technische Universität Darmstadt, Goethe-Universität Frankfurt am Main, and Darmstadt University of Applied Sciences. With more than 600 scientists, ATHENE is Europe's most prominent cybersecurity research center and Germany’s leading scientific research institution in this domain. ATHENE is supported by the German Federal Ministry of Education and Research (BMBF) and the Hessian Ministry for Higher Education, Research, Science and the Arts (HMWK). Further information about ATHENE can be found at https://www.athene-center.de/en/.
Press Contact: Mrs. Cornelia Reitz, cornelia.reitz@athene-center.de
Subscribe to releases from news aktuell GmbH
Subscribe to all the latest releases from news aktuell GmbH by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from news aktuell GmbH
Vyoma awarded ESA data procurement contract for space-based data on small space debris24.2.2026 10:53:34 CET | Press release
(Munich, February 24th, 2026) Vyoma, a Munich-based company providing Space Domain Awareness (SDA) capabilities, has been selected as the winner of the ESA tender on ”Data Procurement for Space-Based Statistical Data on Small Space Debris Phase 1”, funded via ESA‘s Space Safety Programme (S2P). ESA’s Meteoroid And Space debris Terrestrial Environment Reference (MASTER) model provides a description of the space environment around Earth, supporting satellite designers, operators and others with risk assessments. Currently, there exists a significant temporal and spatial knowledge gap for observations of space debris with sizes smaller than the detection limit of ground-based sensors. Vyoma's Flamingo-1 satellite is ideally positioned to generate the image data ESA is seeking. Flying “in-situ” at an altitude of 510 km, Flamingo-1's instrument can monitor large volumes of space at once. This sensor detects objects at long and short distances and captures small and fast objects reliably, im
Medi-Globe Launches mAI Companion® — the World’s First Real Time AI Assistant for Pancreatic EUS, Co Developed with IHU Strasbourg —Now MDR CE Marked and Available for Clinical Use in Europe24.2.2026 10:00:00 CET | Press release
Rohrdorf (Achenmühle), Germany — February 24, 2026 — Medi-Globe today announced the launch of mAI Companion®, a real-time medical AI solution designed to assist physicians in detecting pancreatic lesions during endoscopic ultrasound (EUS) — addressing one of the deadliest and most difficult-to-detect cancers, where earlier identification can dramatically change patient outcomes.
Grünenthal licenses exclusive Australian rights to Qutenza® to Clinect24.2.2026 08:43:52 CET | Press release
Aachen, Germany & Victoria, Australia, 24 February 2026 – Grünenthal, a global leader in pain management and related diseases, and Clinect Pty Ltd ("Clinect"), an Australian based company focussed on supporting access to unique products, announced today that they have entered into a definitive agreement whereby Clinect will have the exclusive Australian rights to Qutenza®, a topical, non-systemic, non-opioid patch indicated for the management of peripheral neuropathic pain. Under the agreement, Clinect will be responsible for obtaining marketing authorisation for Qutenza® in Australia and, upon approval, marketing and distributing the product in Australia.
Clean energy needs a clean planet: PLAN-B NET ZERO and everwave launch joint initiative20.2.2026 13:26:02 CET | Press release
(Berlin, Germany) A strong start to 2026. PLAN-B NET ZERO enters into a partnership with the Aachen-based environmental scale-up everwave. With the guiding principle ‘1 euro = 1 kilogram of waste’, the partners recovered 10,000 kilograms of waste from rivers in Cambodia at the start of the initiative Around 11 million tonnes of plastic waste enter the oceans every year. Without effective countermeasures, this volume could almost triple by 2040. Studies show that about 80 percent of marine plastic reaches the sea via roughly 1,656 rivers worldwide. To date, everwave has removed more than 2.4 million kilograms of plastic from rivers in Cambodia, Albania, and Thailand. The company uses waste collection boats, barriers, and manual cleanups to stop plastic before it reaches the oceans. At the same time, mobile sorting and recycling solutions return materials efficiently to the circular economy. AI support optimizes collection routes to clean as many waterways as possible in a sustainable wa
Grünenthal’s proprietary NaV 1.8 inhibitor enters clinical development18.2.2026 11:52:51 CET | Press release
Aachen, Germany, 18 February 2026 – Grünenthal announced today that the first healthy volunteers have been enrolled in a Phase I trial of its voltage-gated sodium channel (NaV) 1.8 inhibitor. The orally administered investigational medicine aims to provide a non-opioid therapy option across a range of acute and chronic pain conditions. Full results of the trial are expected in the second half of 2026.
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom