ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

CISA Warns of Actively Exploited D-Link Router Vulnerabilities

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2014-100005
CSRF in D-Link DIR-600 Router Allows Unauthorized Configuration Changes

The D-Link DIR-600 router contains a cross-site request forgery (CSRF) flaw, CWE-352, in its administrative web interface. An attacker triggers it by inducing a user with an active administrator session to the router to load attacker-controlled content, which silently submits forged configuration-change requests using the hijacked admin session. A successful attack lets the attacker alter the router's configuration, potentially redirecting traffic or establishing persistence on the device. All associated hardware revisions of the DIR-600 are legacy end-of-life/end-of-service products, so users of this model are affected. CISA added the issue to the KEV catalog on 2024-05-16, indicating observed exploitation, and EPSS assigns a 42.4% probability of exploitation in the next 30 days (99th percentile); ransomware use is unknown.

Do: Because the DIR-600 is end-of-life/end-of-service and the data indicates no fixed firmware, CISA's required action is to retire and replace affected hardware per vendor instructions. If replacement must be deferred, disable WAN/remote administration, avoid staying logged in to the admin interface while browsing other sites, restrict admin access to trusted clients, and check the device's DNS settings and administrator credentials for signs of tampering.

48% KEV
  • D-Link DIR-600 Router
massplausibly millions of legacy units worldwide, with hundreds of thousands of legacy D-Link devices still visible in public internet scans
CVE-2021-40655
Unauthenticated credential disclosure in D-Link DIR-605 router (getcfg.php)

CVE-2021-40655 is an unauthenticated information-disclosure flaw (CWE-863, incorrect authorization) in D-Link DIR-605 routers running B2 hardware revision firmware version 2.01MT. An attacker can trigger it remotely by forging a crafted POST request to the device's /getcfg.php page, with no credentials or user interaction required. The flaw returns the router's user name and password, giving the attacker valid credentials for the device's management interface and exposing confidential configuration data; the CVSS 7.5 score reflects high confidentiality impact with no direct integrity or availability impact. Only the legacy DIR-605 is affected, and per CISA all associated hardware revisions have reached end-of-life/end-of-service, so no fixed firmware should be expected from the vendor. CISA added the bug to its Known Exploited Vulnerabilities catalog on 2024-05-16 amid headlines warning of actively exploited D-Link router flaws, a public proof-of-concept exists on GitHub, and EPSS assigns an 86.7% probability of exploitation within 30 days (percentile 100); ransomware use is unknown.

Do: Because the DIR-605 is end-of-life/end-of-service with no fixed firmware available, CISA's required action is to retire and replace affected units per vendor instructions. As interim mitigation, restrict or disable WAN-side (internet-facing) management so /getcfg.php is unreachable from the internet, and rotate any exposed administrative credentials. Defenders with internet-facing D-Link routers should inventory against this KEV entry and prioritize replacement of remaining DIR-605 units.

7.587% KEV PoC
  • D-Link DIR-605 router, B2 hardware revision (CPE entry: dir-605l firmware) Firmware 2.01MT
largetens of thousands of internet-exposed legacy units (estimated; the historical deployed base is likely far larger)
CVE-2024-22026
+2 in the same advisory: …46807 …46806
A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and execute arbitrary commands

A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and execute arbitrary commands on the appliance.

NVD description · AI analysis pending
6.71%
  • ivanti endpoint manager mobile
Full article501 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananMay 17, 2024Vulnerability / Network Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two security flaws impacting D-Link routers to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

The list of vulnerabilities is as follows -

  • CVE-2014-100005 - A cross-site request forgery (CSRF) vulnerability impacting D-Link DIR-600 routers that allows an attacker to change router configurations by hijacking an existing administrator session
  • CVE-2021-40655 - An information disclosure vulnerability impacting D-Link DIR-605 routers that allows attackers to obtain a username and password by forging an HTTP POST request to the /getcfg.php page

There are currently no details on how these shortcomings are exploited in the wild, but federal agencies have been urged to apply vendor-provided mitigations by June 6, 2024.

It's worth noting that CVE-2014-100005 affects legacy D-Link products that have reached end-of-life (EoL) status, necessitating that organizations still using them retire and replace the devices.

The development comes as the SSD Secure Disclosure team revealed unpatched security issues in DIR-X4860 routers that could enable remote unauthenticated attackers to access the HNAP port in order to obtain elevated permissions and run commands as root.

"By combining an authentication bypass with command execution the device can be completely compromised," it said, adding the issues impact routers running firmware version DIRX4860A1_FWV1.04B03.

SSD Secure Disclosure has also made available a proof-of-concept (PoC) exploit, which employs a specially crafted HNAP login request to the router's management interface to get around authentication protections and achieve code execution by taking advantage of a command injection vulnerability.

D-Link has since acknowledged the issue in a bulletin of its own, stating a fix is "Pending Release / Under Development." It described the vulnerability as a case of LAN-side unauthenticated command execution flaw.

Ivanti Patches Multiple Flaws in Endpoint Manager Mobile (EPMM)

Cybersecurity researchers have also released a PoC exploit for a new vulnerability in Ivanti EPMM (CVE-2024-22026, CVSS score: 6.7) that could permit an authenticated local user to bypass shell restriction and execute arbitrary commands on the appliance.

"This vulnerability allows a local attacker to gain root access to the system by exploiting the software update process with a malicious RPM package from a remote URL," Redline Cyber Security's Bryan Smith said.

The problem stems from a case of inadequate validation in the EPMM command-line interface's installation command, which can fetch an arbitrary RPM package from a user-provided URL without verifying its authenticity.

CVE-2024-22026 impacts all versions of EPMM before 12.1.0.0. Also patched by Ivanti are two other SQL injection flaws in the same product (CVE-2023-46806 and CVE-2023-46807, CVSS scores: 6.7) that could allow an authenticated user with appropriate privilege to access or modify data in the underlying database.

While there is no evidence that these flaws have been exploited, users are advised to update to the latest version to mitigate potential threats.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/05/cisa-warns-of-actively-exploited-d-link.html