PT-2021-4449 · D Link · Dsr-500N
Daniel Nussko
·
Published
2021-08-23
·
Updated
2024-08-04
·
CVE-2021-39615
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DSR-500N version 1.02
D-Link DSR-500N versions prior to 2.12/2
Description
The issue is related to hard-coded credentials for undocumented user accounts in the '/etc/passwd' file. If an attacker recovers the cleartext password of the identified hash value, they can log in via SSH or Telnet and gain access to the underlying embedded Linux operating system on the device.
Recommendations
For D-Link DSR-500N version 1.02, update to version 2.12/2 to resolve the issue.
For D-Link DSR-500N versions prior to 2.12/2, update to version 2.12/2 to resolve the issue.
As a temporary workaround, consider restricting access to the '/etc/passwd' file and limiting SSH and Telnet connections to minimize the risk of exploitation.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dsr-500N