what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

D-Link Bypass / Buffer Overflow

D-Link Bypass / Buffer Overflow
Posted May 28, 2015
Authored by Gergely Eberhardt

SEARCH-LAB performed an independent security assessment on four different D-Link devices. The assessment has identified altogether 53 unique vulnerabilities in the latest firmware (dated 30-07-2014). Several vulnerabilities can be abused by a remote attacker to execute arbitrary code and gain full control over the devices.

tags | advisory, remote, overflow, arbitrary, vulnerability, bypass
advisories | CVE-2014-7857, CVE-2014-7858, CVE-2014-7859, CVE-2014-7860
SHA-256 | 1171f7b6ef3b9988b436da7e93b267aab8de442398c22cf0acfa717cbfa2ab37

D-Link Bypass / Buffer Overflow

Change Mirror Download
Overwiew
--------
SEARCH-LAB performed an independent security assessment on four
different D-Link devices. The assessment has identified altogether 53
unique vulnerabilities in the latest firmware (dated 30-07-2014).
Several vulnerabilities can be abused by a remote attacker to execute
arbitrary code and gain full control over the devices. We list below
several of the problematic areas, where the most critical findings were
discovered:
- Authentication can be bypassed in several ways, allowing an attacker
to take full control over the device without the need to exploit any
programming or design bugs.
- We found a few half-baked security workarounds to fix earlier
vulnerabilities that introduced even more serious problems, leading to
command injection and the possibility to take full control over the device.
- Even though there were several security patches and workarounds in the
session management part of the code, where we still found serious
problems. It was still possible to perform unauthenticated file upload
to an arbitrarily chosen location, which also lead to the possibility
for an attacker to take full control over the device.
- Default users (root, nobody) can be used during authentication, and
the administrator cannot change the default (empty) password of these
users from the user interface.

Details and CVEs
----------------
For the specific details see our full report in [SL-ADV]. We suppose
that some of the vulnerabilities were discovered by other researchers
too, but we saw it reasonable and useful to publish our findings in such
a comprehensive study. Naturally in the report we tried to find and
reference all of the previous publications that may have found the same
problems.
We obtained the following CVE numbers for the above described
vulnerabilities:
- CVE-2014-7858: Check_login bypass vulnerability in DNR-326
- CVE-2014-7859: Buffer overflow in login_mgr.cgi and in file_sharing.cgi
- CVE-2014-7860: Unauthenticated photo publish
We also reported two other authentication bypass vulnerabilities
(CVE-2014-7857) to D-Link; but since these problems have not been
addressed correctly yet, we will only publish them after 22/06/2015.

Affected devices
----------------
Main targeted devices during the assessment:
- DNS-320, Revision A: 2.03, 13/05/2013
- DNS-320L, 1.03b04, 11/11/2013
- DNS-327L, 1.02, 02/07/2014
- DNR-326, 1.40b03, 7/19/2013

Other devices were influenced by one or more vulnerabilities:
- DNS-320B, 1,02b01, 23/04/2014
- DNS-345, 1.03b06, 30/07/2014
- DNS-325, 1.05b03, 30/12/2013
- DNS-322L, 2.00b07

See [SL-ADV] for the complete vulnerability matrix at the time of the
assessment. We note that other devices may also be vulnerable.

Solution
--------
Most of the vulnerabilities were fixed in:
- DNS-320L 1.04.B12
- DNS-327L 1.03.B04

Some of the vulnerabilities were fixed in:
- DNR-326 2.10.B03
- DNR-322L 2.10.B03

Besides installing the patches, where available, we highly recommend not
to expose the web interface of the DNS and DNR devices to the internet.
Since the devices use the UPnP feature, you should disable it in the router.

Credits
-------
These vulnerabilities were discovered and researched by Gergely
Eberhardt (@ebux25) from SEARCH-LAB Ltd. (www.search-lab.hu)

References
----------
[SL-ADV] Security Advisory, MULTIPLE VULNERABILITIES IN D-LINK DNS-320,
320L, 327L AND DNR-326 DEVICES,
http://www.search-lab.hu/media/D-Link_Security_advisory_3_0_public.pdf
[DNS-320] http://support.dlink.com/ProductInfo.aspx?m=DNS-320
[DNS-320L] http://support.dlink.com/ProductInfo.aspx?m=DNS-320L
[DNS-327L] http://support.dlink.com/ProductInfo.aspx?m=DNS-327L
[DNS-345] http://support.dlink.com/ProductInfo.aspx?m=DNS-345
[DNS-325] http://support.dlink.com/ProductInfo.aspx?m=DNS-325
[DNR-326] http://support.dlink.com/ProductInfo.aspx?m=DNR-326
[DNR-322L] http://support.dlink.com/ProductInfo.aspx?m=DNR-322L
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    28 Files
  • 16
    Jul 16th
    6 Files
  • 17
    Jul 17th
    34 Files
  • 18
    Jul 18th
    6 Files
  • 19
    Jul 19th
    34 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    19 Files
  • 23
    Jul 23rd
    17 Files
  • 24
    Jul 24th
    47 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close