
A serious remote code execution vulnerability in a series of D-Link servers was publicly disclosed by security researchers last week.
Fortinet's FortiGuard Labs reported that the vulnerability, which is essentially the root of the problem and identified as CVE-2019-16920, was discovered in September 2019.
According to Fortinet researcher Thanh Nguyen Nguyen, the unauthenticated command injection vulnerability affects D-Link firmware in the DIR-655, DIR-866L, DIR-652, and DHP-1565 products
The vulnerability is described as an RCE pushed by attackers, sending arbitrary inputs to a “PingTest” gateway interface, which in turn leads to command injection and fully affects the system. The flaw is rated as CVSS v3.1 9.8 and CVSS v2.0 10.0.
According to Fortinet, attackers can execute a remote login function that is insufficiently authenticated in order to trigger the vulnerability.
The bad authentication check allows code to be executed, whether the user has permission to do so or not, to send an HTTP POST request via PingTest, allowing attackers to either steal administrator credentials or install a backdoor.
On September 22, researchers disclosed their findings regarding the vulnerability in D-Link servers.
Given the age of these servers, it's not surprising that D-Link has chosen not to issue a patch for the vulnerability. Both the devices and their firmware have expiration dates and support for them eventually ends. Therefore, users of these servers should consider replacing them to reduce the risk of attack .
