PT-2013-5931 · D Link+2 · D-Link Di-604+8
Craig Heffner
·
Published
2013-10-19
·
Updated
2023-04-26
·
CVE-2013-6026
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-100
D-Link DIR-120
D-Link DI-624S
D-Link DI-524UP
D-Link DI-604S
D-Link DI-604UP
D-Link DI-604+
D-Link TM-G5240
Planex BRL-04R
Planex BRL-04UR
Planex BRL-04CW
Alpha Networks routers (affected versions not specified)
Description
The issue allows remote attackers to bypass authentication and modify settings on the affected routers. This is achieved by using a specific
User-Agent HTTP header, namely xmlset roodkcableoj28840ybtide. There have been real-world incidents where this issue was exploited, specifically in October 2013.Recommendations
For D-Link DIR-100, update the firmware to remove the vulnerable
User-Agent header handling.
For D-Link DIR-120, restrict access to the web interface until a patch is available.
For D-Link DI-624S, avoid using the web interface for critical operations until the issue is resolved.
For D-Link DI-524UP, consider disabling remote access to the web interface as a temporary workaround.
For D-Link DI-604S, update the router's configuration to limit access to the web interface.
For D-Link DI-604UP, change the default settings to prevent unauthorized access.
For D-Link DI-604+, apply the latest security patch to fix the authentication bypass issue.
For D-Link TM-G5240, modify the User-Agent header handling to prevent exploitation.
For Planex BRL-04R, restrict the use of the vulnerable User-Agent header.
For Planex BRL-04UR, update the router's software to remove the vulnerable code.
For Planex BRL-04CW, disable the web interface until a fix is available.
For Alpha Networks routers, at the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alpha Networks Routers
D-Link Di-524
D-Link Di-604
D-Link Di-624
D-Link Dir-100
D-Link Dir-120
D-Link Tm-G5240
Planex Brl-04Cw
Planex Brl-04R