Skip to main content

D-Link Router Authentication Bypass Backdoor Vulnerability

Last Update Date: 3 Dec 2013 Release Date: 15 Oct 2013 3490 Views

RISK: High Risk

TYPE: Servers - Network Management

TYPE: Network Management

A vulnerability was reported in D-Link Routers. A remote user can gain administrative access on the target device.

 

A remote user can send a specially crafted HTTP request with the HTTP User-Agent set to 'xmlset_roodkcableoj28840ybtide' to bypass authentication and gain administrative access on the target device.

 

The vulnerability is due to a non-secure backdoor.

 

Note: Currently, there is no patch is available


Impact

  • Elevation of Privilege

System / Technologies affected

  • firmware v1.13 for the DIR-100 revA

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier

  • No CVE information is available

Source


Related Link