Certain models of D-Link wireless routers contain an undisclosed factory testing backdoor. Unauthenticated attackers on the local area network can force the device to enable Telnet service by accessing a specific URL and can log in by using the administrator credentials obtained from analyzing the firmware.
Solution:
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://www.twcert.org.tw/tw/cp-132-7879-da630-1.html | third party advisory |
https://www.twcert.org.tw/en/cp-139-7880-629f5-2.html | third party advisory |
https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10398 | vendor advisory |