
D-Link DNS-320 devices have been discovered to have a dangerous vulnerabilitythat could allow hackers to remotely take control of such a device and access the files stored there.
Researchers at Vietnam-based CyStack Security discovered and reported the vulnerability in mid-August. About a month later, the provider released guidance on the vulnerability, but it turned out that the vulnerability had actually been accidentally patched in April when D-Link released firmware version 2.06b01 to address a vulnerability exploited by the Cr1ptT0r ransomware to infect D-Link NAS devices.
The flaw, CVE-2019-16057, has been rated CVSS 10 by CyStack. It affects D-Link DNS-320 devices with firmware version 2.05b10 and later.
CyStack's Nguyen Dang told SecurityWeek that the vulnerability can be exploited directly from the internet and says there are at least 800 vulnerable devices that could be targeted from the web. Nguyen noted that all D-Link DNS-320 devices were vulnerable to attacks before the issue was fixed in April.
The vulnerability has been described as a command injection issue, present in the connection module for the DNS-320 management interface.
The affected module, /cgi/login_mgr.cgi, includes a parameter named “port” that can be affected. An unauthenticated attacker could abuse this parameter to execute arbitrary commands with root, allowing them to take complete control of a targeted device and the files stored on it.
CyStack published a blog post describing the vulnerability and how researchers discovered its existence.
