An issue was discovered on D-Link DSR-250 3.17 devices. Insufficient validation of configuration file checksums could allow a remote, authenticated attacker to inject arbitrary crontab entries into saved configurations before uploading. These entries are executed as root.
The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.
Link | Tags |
---|---|
https://www.dlink.com/en/security-bulletin | vendor advisory |
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10195 | vendor advisory |
https://www.digitaldefense.com/news/zero-day-vuln-d-link-vpn-routers/ | third party advisory |