PT-2020-1848 · D Link · D-Link Dir-867+2
Chung96Vn
·
Published
2020-02-21
·
Updated
2021-04-23
·
CVE-2020-8864
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-867 versions 1.10B04
D-Link DIR-878 versions 1.10B04
D-Link DIR-882 versions 1.10B04
Description
The issue is related to errors in handling empty passwords in the HNAP strncmp component of the D-Link DIR-867, DIR-878, and DIR-882 routers' firmware. This allows a remote attacker to change the administrator password. The specific flaw exists within the handling of HNAP login requests, resulting from the lack of proper handling of empty passwords. An attacker can leverage this vulnerability to execute arbitrary code on the router.
Recommendations
For D-Link DIR-867 version 1.10B04, update the firmware to a version that fixes the HNAP login request handling issue.
For D-Link DIR-878 version 1.10B04, update the firmware to a version that fixes the HNAP login request handling issue.
For D-Link DIR-882 version 1.10B04, update the firmware to a version that fixes the HNAP login request handling issue.
As a temporary workaround, consider restricting access to the HNAP login requests until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D-Link Dir-867
D-Link Dir-878
D-Link Dir-882