PT-2020-1848 · D Link · D-Link Dir-867+2

Chung96Vn

·

Published

2020-02-21

·

Updated

2021-04-23

·

CVE-2020-8864

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DIR-867 versions 1.10B04 D-Link DIR-878 versions 1.10B04 D-Link DIR-882 versions 1.10B04
Description The issue is related to errors in handling empty passwords in the HNAP strncmp component of the D-Link DIR-867, DIR-878, and DIR-882 routers' firmware. This allows a remote attacker to change the administrator password. The specific flaw exists within the handling of HNAP login requests, resulting from the lack of proper handling of empty passwords. An attacker can leverage this vulnerability to execute arbitrary code on the router.
Recommendations For D-Link DIR-867 version 1.10B04, update the firmware to a version that fixes the HNAP login request handling issue. For D-Link DIR-878 version 1.10B04, update the firmware to a version that fixes the HNAP login request handling issue. For D-Link DIR-882 version 1.10B04, update the firmware to a version that fixes the HNAP login request handling issue. As a temporary workaround, consider restricting access to the HNAP login requests until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01122
CVE-2020-8864
ZDI-20-268

Affected Products

D-Link Dir-867
D-Link Dir-878
D-Link Dir-882