National Research Center for Applied Cybersecurity ATHENE: Severe Vulnerabilities Discovered in Software to Protect Internet Routing
12.4.2024 08:49:14 CEST | news aktuell GmbH | Press release
A research team from the National Research Center for Applied Cybersecurity ATHENE led by Prof. Dr. Haya Schulmann has uncovered 18 vulnerabilities in crucial software components of Resource Public Key Infrastructure (RPKI). RPKI is an Internet standard meant to protect Internet traffic from being hijacked by hackers. By now, all affected vendors provided patches for their products. The vulnerabilities could have had devastating consequences: Internet hijacks have already been exploited, e.g., for phishing passwords and other sensitive information, tricking certificate authorities into issuing fraudulent Web certificates, stealing cryptocurrency, distributing malware, and poisoning caches of DNS servers.

Frankfurt and Darmstadt, April 2024
The ATHENE team consisting of Prof. Dr. Haya Schulmann and Niklas Vogel, both from Goethe University of Frankfurt, Donika Mirdita from TU Darmstadt, and Prof. Dr. Michael Waidner from TU Darmstadt and Fraunhofer SIT uncovered and disclosed 18 vulnerabilities. The National Vulnerability Database (NVD), operated by the US National Institute of Standards and Technology (NIST), assigned five Common Vulnerabilities and Exposures (CVE) entries to these vulnerabilities, some critical with a score of 9.3 out of 10. The team used a testing tool, CURE, which they developed specifically for this project and which ATHENE makes available free of charge to all developers of RPKI software. The researchers found vulnerabilities in all popular implementations of the validator component of RPKI. They range between crashes, violation of standard behavior, and even severe bugs that allow a network adversary to completely take over an RPKI certificate hierarchy in order to inject its own trust anchor – effectively being able to forge authentic and valid yet bogus routing information (i.e., BGP announcements). It is unknown whether any of the vulnerabilities were already exploited by hackers in the wild.
RPKI is a relatively new standard. Today, about 50% of the Internet’s network prefixes are covered by RPKI certificates, and 37.8% of all Internet domains validate RPKI certificates. In particular, many large providers and operators support RPKI, e.g., Amazon Web Services, Cogent, Deutsche Telekom, Level 3, and Zayo.
The research work was carried out in the ATHENE research area Analytic Based Cybersecurity (ABC) (more information at https://abc.athene-center.de/en/ ) and appeared at the 2024 Network and Distributed System Security (NDSS) Symposium in San Diego, California, USA. The research paper can be downloaded from https://www.ndss-symposium.org/ndss-paper/the-cure-to-vulnerabilities-in-rpki-validation/. The testing tool CURE developed and used by the researchers to uncover the vulnerabilities can be downloaded from https://github.com/rp-cure/rp-cure.
The National Research Center for Applied Cybersecurity ATHENE is a research center of the Fraunhofer Society that brings together the Fraunhofer Institutes for Secure Information Technology (SIT) and for Computer Graphics Research (IGD), Technische Universität Darmstadt, Goethe-Universität Frankfurt am Main, and Darmstadt University of Applied Sciences. With more than 600 scientists, ATHENE is Europe's most prominent cybersecurity research center and Germany’s leading scientific research institution in this domain. ATHENE is supported by the German Federal Ministry of Education and Research (BMBF) and the Hessian Ministry for Higher Education, Research, Science and the Arts (HMWK). Further information about ATHENE can be found at https://www.athene-center.de/en/.
Press Contact: Mrs. Cornelia Reitz, cornelia.reitz@athene-center.de
Subscribe to releases from news aktuell GmbH
Subscribe to all the latest releases from news aktuell GmbH by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from news aktuell GmbH
FarmDroid Field Robot Featured in award-winning “Clarkson’s Farm”: Autonomous Seeding and Weeding Robot in the Spotlight on Prime Video Series12.6.2026 09:02:28 CEST | Press release
(Odense, Denmark, June 11, 2026) The hit Prime Video series Clarkson’s Farm features the autonomous field robot FarmDroid FD20 in its latest episode, airing today. Operating on Jeremy Clarkson’s Diddly Squat Farm, the solar-powered robot demonstrates how automation, precision seeding, and mechanical weeding can help farmers improve efficiency while supporting more sustainable crop production. Clarkson first discovered FarmDroid at LAMMA 2025 while looking for ways to reduce manual labour on the farm. He was impressed by the robot’s ability to carry out both seeding and weed control with exceptional precision. The FarmDroid FD20 autonomously performs seeding and mechanical weeding with GPS accuracy of up to eight millimetres. By recording the exact position of every seed, it can remove weeds between and within crop rows, reducing chemical use, protecting soil health, and lowering labour requirements. “Having our robot featured in an internationally successful series like Clarkson’s Farm
HEIDELBERG forges ahead with transformation – foundations laid for medium-term growth10.6.2026 08:57:51 CEST | Press release
Dual-use technology approach on target – establishing new areas of business based on core expertise boosts strategic diversification Strong partnerships – new Memorandum of Understanding to be announced at ILA between ONBERG and Ukrainian company Core business stable – global positioning ensures robust development and underlines market leadership Focus on efficiency – cost base streamlined and competitiveness strengthened Financial year 2025/2026 – EBITDA margin down on previous year, while sales and net result after taxes improve Outlook for financial year 2026/2027 – challenging geopolitical environment, systematic expansion of HEIDELBERG Technology growth segment
The Virchow Prize 2026 Awarded for Pioneering Work on Ebola, Advancing Global Epidemic Preparedness and Fostering Global Solidarity3.6.2026 12:37:54 CEST | Press release
Jean-Jacques Muyembe and Peter Piot are being honored with the international award of €500,000 for exceptional life-long leadership spanning five decades since the first outbreak of Ebola
Hidden AI agents could become the new gatekeepers of commerce, warns new Fintech 2040 paper3.6.2026 12:25:33 CEST | Press release
A new Fintech 2040 paper from Professor Roland Frank explores how AI agents are moving from passive assistants to autonomous actors capable of searching, selecting and purchasing products on behalf of consumers — fundamentally reshaping the future of ecommerce and payments.
OSD supplies Principality of Andorra with EU Standard Driving Licence and Advanced Personalisation System3.6.2026 09:00:00 CEST | Press release
Andorra/Vienna – The Austrian State Printing Company (OSD) is proud to supply the Principality of Andorra with a new EU‑standardized driving licence card and a fully integrated state‑of‑the‑art personalisation platform by OSD. The solution, delivered to the Andorran Departament de Seguretat Industrial i Vehicles (Ministeri de Presidència, Economia, Treball i Habitatge), went live in the end of 2025 and sets a new benchmark for security, usability and European compliance.
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom