main
Report a problem

D-Link Leaves Critical Hole Open for 5 Months, And Counting

Dice   on 01 July 2006 - 15:58 · 47 comments & 27175 views

Advertisement (Why?)
Security vulnerability discoveries were reported last February to D-Link and surprisingly they still have not been fixed yet! The vulnerability allows remote code to be executed through the routersfirmware potentially leaving affected customers vulnerable to attack.The vulnerability can give an attacker complete control over any andall network traffic.

The effected products are:
  • DI-524 (Wireless)
  • DI-604*
  • DI-624 (Wireless)
  • DI-784* (Wireless)
  • EBR-2310*
  • WBR-1310 (Wireless)
  • WBR-2310 (Wireless)
*(Denotes firmware update available)

D-Linkhas hardly said a word publicly about the issue and has only patched asmall portion of the devices affected. In fact the only word directlyfrom D-Link is from a supposed support staff member in a post on the DSLReports.com forums.According to that person the issue has to do with UPnP, a LAN sideprotocol thus reasoning that the problem isn’t susceptible to WAN orinternet side attacks.

Unfortunately because some of theeffected routers are wireless it isn’t unlikely that an attacker mightcompromise the router by gaining access to the wireless portion of therouter and injecting malicious code. Even secured wireless routersaren’t foolproof and given enough time and resources these too can becompromised. The only advice that can be given at this point fromsecurity researchers is to discontinue using the affected routers untila fix is published by D-Link as there is nothing the consumer can to domitigate the issue themselves.

D-Link was also recently in the news when its engineers began using a FreeBSD NTP top level server as the primary time server for its devices. The issue was solved eventually, and new routers stopped using the NTP server.

News source: DailyTech

Post a comment · Send to friend Comments · There are 47 additional comments
#1 shockz on 01 Jul 2006 - 16:36
I've got the WBR-2310... good router aside for this problem. Used to have a linksys router and those kept malfunctioning. I'm not going to run out and buy a new one as i've got the SSID Broadcast enabled and nobody around here even knows what wireless is. I dobut many people go war driving by me as I'm far back in a dead end street next to a lake which makes a ton of interferance for signals. So yeah... I'm going to put this on my annoying, but not a big deal list.
(1 reply) #2 on 01 Jan 1970 - 00:00
#2.1 shockz on 01 Jul 2006 - 16:39
Don't bother with Pre-N... DLink, Linksys, Belkin (not sure about netgear) now has 802.11n... nothing pre about it. I think they also have the Mimo which is great. Netgear is ok... i don't like the security settings on them... seem to be lacking in that area unless you get the super high end models.

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)