D-Link Home Routers Open To Remote Takeover Will Remain Unpatched

Peter Reutemann <[email protected]> Wed, 9 Oct 2019 11:41:34 +1300
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12Laf-scAD4mYDfedcPtBMo3cbHxxqTsBzzf+dwa-Q9+KA@mail.gmail.com>
'D-Link won't patch a critical unauthenticated command-injection
vulnerability in its routers that could allow an attacker to remotely
take over the devices and execute code. Threatpost reports:

The vulnerability (CVE-2019-16920) exists in the latest firmware for
the DIR-655, DIR-866L, DIR-652 and DHP-1565 products, which are Wi-Fi
routers for the home market. D-Link last week told Fortinet's
FortiGuard Labs, which first discovered the issue in September, that
all four of them are end-of-life and no longer sold or supported by
the vendor (however, the models are still available as new via
third-party sellers). The root cause of the vulnerability, according
to Fortinet, is a lack of a sanity check for arbitrary commands that
are executed by the native command-execution function. Fortinet
describes this as a "typical security pitfall suffered by many
firmware manufacturers." With no patch available, affected users
should upgrade their devices as soon as possible. '

-- source: https://it.slashdot.org/story/19/10/08/2016251

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list -- [email protected] | To unsubscribe send an email to [email protected]
Unsubscribe: https://list.waikato.ac.nz/postorius/lists/wlug.list.waikato.ac.nz