Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2013-6026: CERT/CC Vulnerability Note VU#248083

The web interface on D-Link DIR-100, DIR-120, DI-624S, DI-524UP, DI-604S, DI-604UP, DI-604+, and TM-G5240 routers; Planex BRL-04R, BRL-04UR, and BRL-04CW routers; and Alpha Networks routers allows remote attackers to bypass authentication and modify settings via an xmlset_roodkcableoj28840ybtide User-Agent HTTP header, as exploited in the wild in October 2013.

CVE
#vulnerability#web#backdoor#auth

D-Link routers authenticate administrative access using specific User-Agent string

Vulnerability Note VU#248083

Original Release Date: 2013-10-17 | Last Revised: 2014-07-29

Overview

Various D-Link routers allow administrative web actions if the HTTP request contains a specific User-Agent string. This backdoor allows an attacker to bypass password authentication and access the router’s administrative web interface. Planex and Alpha Networks devices may also be affected.

Description

CVE-2013-6026:

According to security researcher Craig Heffner, the firmware for various D-Link routers contains a backdoor that allows unauthenticated remote users to bypass the routers’ password authentication mechanism. A router’s internal web server will accept and process any HTTP requests that contain the User-Agent string “xmlset_roodkcableoj28840ybtide” without checking if the connecting host is authenticated.

D-Link has confirmed that the affected D-Link routers disable web configuration from the WAN by default.

According to D-Link, the following D-Link routers are affected:

  • DIR-100
  • DIR-120
  • DI-624S
  • DI-524UP
  • DI-604S
  • DI-604UP
  • DI-604+
  • TM-G5240

According to the original vulnerability report, the following Planex routers are likely affected:

  • BRL-04R
  • BRL-04UR
  • BRL-04CW

It appears that Alpha Networks may be the OEM for routers branded by D-Link and Planex (and probably other vendors). It is not clear where in the supply chain the backdoor was added, so routers from any of these vendors may be affected.

CVE-2013-6027:
A separate stack overflow vulnerability in the management web server has also been reported.

Impact

An unauthenticated remote attacker can take any action as an administrator using the remote management web server.

Solution

D-Link is maintaining a page to inform users of this issue and provide updates as patches are released.

Restrict Access

Restrict access to the administrative web server by disabling remote management features or by blocking HTTP requests on the external WAN interface. The administrative web server may listen on ports 80/tcp or 8080/tcp.

D-Link has confirmed that the affected D-Link routers disable web configuration from the WAN by default. There is some evidence that at least one ISP may have deployed vulnerable routers with the remote WAN management enabled.

Vendor Information

Filter by content: Additional information available

Sort by:

CVSS Metrics

Group

Score

Vector

Base

8.3

AV:A/AC:L/Au:N/C:C/I:C/A:C

Temporal

7.5

E:F/RL:W/RC:C

Environmental

5.6

CDP:ND/TD:M/CR:ND/IR:ND/AR:ND

References****Acknowledgements

Thanks to Craig Heffner of /DEV/TTYS0 for reporting this vulnerability.

This document was written by Todd Lewellen.

Other Information

CVE IDs:

CVE-2013-6026, CVE-2013-6027

Date Public:

2013-10-12

Date First Published:

2013-10-17

Date Last Updated:

2014-07-29 23:29 UTC

Document Revision:

34

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907