PT-2019-4703 · D Link · D-Link Dap-1330

Chung96Vn

·

Published

2019-12-26

·

Updated

2020-02-28

·

CVE-2020-8861

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DAP-1330 versions 1.10B01 BETA
Description The issue is related to the incorrect implementation of the HNAP authentication algorithm in the D-Link DAP-1330 Wi-Fi range extender. This allows network-adjacent attackers to bypass authentication. The specific flaw exists within the handling of HNAP login requests, resulting from the lack of proper handling of cookies. An attacker can leverage this vulnerability to execute arbitrary code on the router.
Recommendations For D-Link DAP-1330 version 1.10B01 BETA, consider disabling the HNAP login functionality until a patch is available to prevent exploitation. Restrict access to the router to minimize the risk of arbitrary code execution. Avoid using the vulnerable HNAP protocol for authentication until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01124
CVE-2020-8861
ZDI-20-265

Affected Products

D-Link Dap-1330