D-Link has patched two critical vulnerabilities in its D-View 8 network management suite that could allow remote attackers to bypass authentication and execute arbitrary code.
See also: Operation Magalenha: Brazilian hackers target Portuguese financial institutions

See also: Buhti ransomware: Uses leaked code for Windows, Linux
D-View is a network management suite developed by Taiwanese networking solutions provider D-Link. It is used by businesses of all sizes to monitor performance, control device, create network maps, and generally manage and administer the network more efficiently and less time-consuming.
Security researchers participating in Trend Micro's Zero Day Initiative (ZDI) discovered six flaws affecting D-View late last year and reported them to the vendor on December 23, 2020.
Two of the vulnerabilities discovered are of critical severity (CVSS score: 9.8) and provide unauthorized attackers with strong influence over affected installations.
The first flaw, identified as CVE-2023-32165, is a remote code execution vulnerability that stems from a lack of proper validation of a user-supplied path before using it in file operations.
An attacker who exploits the vulnerability could execute code with SYSTEM privileges, which, for Windows, would be executed with the highest privileges, potentially allowing complete system takeover.
See also: Intellexa's Technical Analysis of Spyware PREDATOR
The second critical flaw has been assigned the identifier CVE-2023-32169 and is an authentication bypass issue resulting from the use of an encoded cryptographic key in the software's TokenUtils class.
Exploiting this flaw allows for privilege escalation, unauthorized access to information, changing configuration and settings in the software, and even installing backdoors and malware.
D-Link has published an advisory for the six flaws reported by ZDI, which affect D-View 8 versions 2.0.1.27 and below, urging administrators to upgrade to the patched version, 2.0.1.28, released on May 17, 2023.
"Once D-Link was made aware of the reported security issues, we immediately began our investigation and began deploying security patches," D-Link's security bulletin states.

Although the vendor "strongly recommends" all users install the security update, the announcement also warns that the update is a "beta or hot-fix software release" that is still in the final testing stage.
This means that upgrading to version 2.0.1.28 may cause issues or introduce instability to D-View, but the severity of the flaws probably outweighs the potential performance issues.
The company advises users to verify the hardware revision of their products by checking the bottom of the label or the configuration table online, before downloading the corresponding firmware update.
Information source: bleepingcomputer.com
