If you have a D-Link DIR-850L router, you should pay attention to this CERT notification. Apparently there’s a flaw in the firmware of this router that allows a remote attacker to run commands on the router. Effectively pwning the device. Now this becomes a really big deal is remote administration is enabled as anyone on the Internet can pwn the router. At present, D-Link has released beta firmware that apparently addresses this issue. However, I would take note of what CERT had to say about that:
The vendor has publicly disclosed the issue along with beta firmware releases (versions 1.14B07 h2ab BETA1 and 2.07B05 h1ke BETA1, depending on the device’s hardware revision), which are available from the product information page, but it is unclear whether the beta releases should be considered a proper solution.
I don’t consider beta anything to be a proper solution. Thus if you have one of these routers, the best that you can do is disable remote administration if you enabled it for whatever reason and wait for D-Link to come out with a proper solution to this.
Related
This entry was posted on March 9, 2017 at 1:28 pm and is filed under Commentary with tags D-Link. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Flaw In D-Link Router Allows For Remote Pwnage Of Said Router
If you have a D-Link DIR-850L router, you should pay attention to this CERT notification. Apparently there’s a flaw in the firmware of this router that allows a remote attacker to run commands on the router. Effectively pwning the device. Now this becomes a really big deal is remote administration is enabled as anyone on the Internet can pwn the router. At present, D-Link has released beta firmware that apparently addresses this issue. However, I would take note of what CERT had to say about that:
The vendor has publicly disclosed the issue along with beta firmware releases (versions 1.14B07 h2ab BETA1 and 2.07B05 h1ke BETA1, depending on the device’s hardware revision), which are available from the product information page, but it is unclear whether the beta releases should be considered a proper solution.
I don’t consider beta anything to be a proper solution. Thus if you have one of these routers, the best that you can do is disable remote administration if you enabled it for whatever reason and wait for D-Link to come out with a proper solution to this.
Share this:
Like this:
Related
This entry was posted on March 9, 2017 at 1:28 pm and is filed under Commentary with tags D-Link. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.