ZeroHour
Security Affairspublished ()ingested @securityaffairs

D-Link fixed 5 flaws on some router models, some of them reached EoL

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-15892
An issue was discovered in apply.cgi on D-Link DAP-1520 devices before 1.10b04Beta02.

An issue was discovered in apply.cgi on D-Link DAP-1520 devices before 1.10b04Beta02. Whenever a user performs a login action from the web interface, the request values are being forwarded to the ssi binary. On the login page, the web interface restricts the password input field to a fixed length of 15 characters. The problem is that validation is being done on the client side, hence it can be bypassed. When an attacker manages to intercept the login request (POST based) and tampers with the vulnerable parameter (log_pass), to a larger length, the request will be forwarded to the webserver. This results in a stack-based buffer overflow. A few other POST variables, (transferred as part of the login request) are also vulnerable: html_response_page and log_user.

NVD description · AI analysis pending
9.82% PoC
  • dlink dap-1520 firmware
CVE-2020-15893
+2 in the same advisory: …15894 …15895
An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02.

An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker can perform command injection by injecting a payload into the Search Target (ST) field of the SSDP M-SEARCH discover packet.

NVD description · AI analysis pending
9.8
group max
21% PoC
  • dlink dir-816l firmware
CVE-2020-15896
An authentication-bypass issue was discovered on D-Link DAP-1522 devices 1.4x before 1.10b04Beta02.

An authentication-bypass issue was discovered on D-Link DAP-1522 devices 1.4x before 1.10b04Beta02. There exist a few pages that are directly accessible by any unauthorized user, e.g., logout.php and login.php. This occurs because of checking the value of NO_NEED_AUTH. If the value of NO_NEED_AUTH is 1, the user has direct access to the webpage without any authentication. By appending a query string NO_NEED_AUTH with the value of 1 to any protected URL, any unauthorized user can access the application directly, as demonstrated by bsc_lan.php?NO_NEED_AUTH=1.

NVD description · AI analysis pending
7.52%
  • dlink dap-1522 firmware
Full article366 words · extracted from securityaffairs.com · click to collapse

D-Link disclosed five severe vulnerabilities affecting some router models which can be exploited by attackers to compromise a network.

D-Link has disclosed five severe vulnerabilities affecting some router models, the flaw could allow a severe network compromise. Unfortunately, some of the impacted models have reached their End-of-Support (“EOS”)/ End-of-Life (“EOL”) date, which means they wouldn’t receive security updates to fix the issues.

The flaws include reflected Cross-Site Scripting (XSS), buffer overflows, bypassing authentication issues, and arbitrary code execution bugs.

The vulnerabilities have been reported by the ACE Team at Loginsoft, below the full list included in the security advisory published by the vendor:

  • CVE-2020-15892 :: Link :: DAP 1520 :: Buffer overflow in the `ssi` binary, leading to arbitrary command execution.
  • CVE-2020-15893 :: Link :: DIR-816L :: Command injection vulnerability in the UPnP via a crafted M-SEARCH packet
  • CVE-2020-15894 :: Link :: DIR-816L :: Exposed administration function, allowing unauthorized access to the few sensitive information.
  • CVE-2020-15895 :: Link :: DIR-816L :: Reflected XSS vulnerability due to an unescaped value on the device configuration webpage.
  • CVE-2020-15896 :: Link :: DAP-1522 :: Exposed administration function, allowing unauthorized access to the few sensitive information.

An unauthenticated attacker with access to the router administration page can exploit the above issues. The attacker would share the same network as the router (i.e. a public Wi-Fi hotspot or internal network) to trigger the flaws. Another attack scenario sees owners of the target D-Link devices having enabled remote access to the router’s web administration interface.

Researchers from Loginsoft also published proof of concept (PoC) exploits for the vulnerabilities.

Some of the flaws were reported in February  9, 2019, other issues date back to March 2020, but all of them have been publicly disclosed on July 22.

The vendor pointed out that DAP-1522 and DIR-816L models that have reached their “end of support” phase, this means that these devices running firmware versions v1.42 (and below) and v12.06.B09 (and below) will receive no security updates remaining vulnerable.

D-Link also released an “Exceptional Beta Patch Release” firmware version v1.10b04Beta02 for the D-Link DAP-1520 model running vulnerable firmware versions v1.10B04 and below.

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, D-Link)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/106351/hacking/d-link-flaws.html