D-Link Router Authentication Bypass Backdoor Vulnerability
RISK: High Risk
TYPE: Servers - Network Management
A vulnerability was reported in D-Link Routers. A remote user can gain administrative access on the target device.
A remote user can send a specially crafted HTTP request with the HTTP User-Agent set to 'xmlset_roodkcableoj28840ybtide' to bypass authentication and gain administrative access on the target device.
The vulnerability is due to a non-secure backdoor.
Note: Currently, there is no patch is available
Impact
- Elevation of Privilege
System / Technologies affected
- firmware v1.13 for the DIR-100 revA
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update avaliable at
http://www.dlink.com/uk/en/support/security (update on 3 Dec 2013)
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with