HomeSecurityVulnerability in D-Link Routers Allows Full Control of the Router

Vulnerability in D-Link Routers Allows Full Control of the Router

A serious unauthenticated remote code execution (RCE) vulnerability has been identified in D-Link routers . The vulnerability allows attackers to gain complete remote control of the router, putting users' security at risk

See also: Malware botnets exploit outdated D-Link routers

D-Link Routers vulnerability

The issue was detected in firmware versions v1.01R1B036_EU_EN and later . This vulnerability was reported by Max Bellia of SECURE NETWORK BVTECH , highlighting the importance of continuous monitoring for system security .

The vulnerability is located in the webproc CGI of the firmware of D-Link Routers. An attacker could exploit it by sending a specially crafted sessionid to the router, thereby compromising the security of the system.

The issue is located in the COMM_MakeCustomMsg function of the libssap library , which does not adequately check the length of incoming data. This security flaw leads to a buffer overflow , allowing arbitrary code execution with root privileges .

See also: D-Link: Recommends replacing old VPN routers due to vulnerability

Successful exploitation of this vulnerability could have serious consequences:

Vulnerability in D-Link Routers Allows Full Control of the Router

Complete router takeover: Attackers could gain administrative access to the device.
Network compromise: Malicious actors could intercept or manipulate network traffic and compromise connected devices.
Malware deployment: The router could be used as a platform to launch further attacks or distribute malware.

D-Link acted quickly upon receiving the report , releasing a patched firmware version for affected routers. The company emphasized its commitment to user privacy and network security, stating that it has a dedicated task force to address emerging threats.

This incident highlights the importance of timely software updates and proactive vulnerability management to protect network devices.

See also: D-Link: Hackers exploit vulnerability affecting EOL NAS devices

Remote Code Execution (RCE) is one of the most serious threats in the field of IT security. It is an attack in which a malicious user manages to execute arbitrary code on a remote computer or system without authorization. Typically, these attacks exploit software weaknesses, such as vulnerabilities in applications or network systems. The consequence of an RCE attack can include gaining access to sensitive data, destroying systems, or even completely compromising an organization. Thus, detecting and addressing these vulnerabilities is critical to ensuring the security of information systems.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS