HomeSecuritySerious vulnerabilities affect dozens of D-Link routers

Serious vulnerabilities affect dozens of D-Link routers

Security researchers Miguel Méndez Zúñiga and Pablo Pollanco from Telefónica Chile have published Proof-of-concept (PoC) exploits for vulnerabilities that allow remote command execution and disclosure information . The specific vulnerabilities affect D-Link routers . D-Link

The two researchers published the technical details for the two vulnerabilities, as well as the PoC videos for their exploitation.

As we mentioned above, one of the two vulnerabilities allows remote command execution. It has been named CVE-2019-17621 and is located in the code used to handle UpnP requests. A malicious hacker, without authorization, could exploit the vulnerability to take control of vulnerable devices. However, the exploitation can only be done if the attacker has access to the network where the vulnerable device is located.

Security researchers published the analysis and Metasploit exploit code on GitHub (Router D-LINK RCE).

According to D-Link: “The initial vulnerability allowed a malicious, unauthorized user to execute commands remotely on the LAN-Side.”

Serious vulnerabilities affect dozens of D-Link routers

The company said that as soon as it was informed of the vulnerability, it released patches to fix it.

D-Link was notified of the security issue by another company in mid-October. However, it initially thought that only the DIR-859 routers were vulnerable. Later, it became known that dozens of D-Link DIR models were vulnerable to the flaw.

The second vulnerability, affecting D-Link routers, allows confidential data. Attackers could obtain a device's VPN configuration file and steal or expose sensitive information from victims.

D-Link has already started releasing firmware updates to fix the security on some of the vulnerable devices. It will soon release more patches and updates for the remaining vulnerable routers. However, the company said that vulnerable models that have reached “end of life” will not receive updates and fixes.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS