D-Link DIR-615 before v20.12PTb04 has a second admin account with a 0x1 BACKDOOR value, which might allow remote attackers to obtain access via a TELNET connection.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
ftp://ftp2.dlink.com/SECURITY_ADVISEMENTS/DIR-615/REVT/DIR-615_REVT_RELEASE_NOTES_20.12PTB04.pdf | release notes vendor advisory |
http://www.rootlabs.com.br/backdoor-dlink-dir-615/ | third party advisory |