CERT mailing list archives
Reports of D-Link Router Backdoor
From: "US-CERT" <US-CERT () ncas us-cert gov>
Date: Fri, 18 Oct 2013 15:15:36 -0500
NCCIC / US-CERT National Cyber Awareness System: Reports of D-Link Router Backdoor [ https://www.us-cert.gov/ncas/current-activity/2013/10/18/Reports-D-Link-Router-Backdoor ] 10/18/2013 03:40 PM EDT Original release date: October 18, 2013 US-CERT is aware of reports that the firmware for various D-Link routers contains a backdoor that allows unauthenticated remote users to bypass the routers' password authentication mechanism. An unauthenticated remote attacker can take any action as an administrator using the remote management web server. D-Link is maintaining a page [ http://www.dlink.com/be/fr/support/security ] to inform users of this issue and provide updates as patches are released. For more information, please see Vulnerability Note VU#248083 [ http://www.kb.cert.org/vuls/id/248083 ]. ________________________________________________________________________ This product is provided subject to this Notification [ http://www.us-cert.gov/privacy/notification ] and this Privacy & Use [ http://www.us-cert.gov/privacy/ ] policy. ________________________________________________________________________ OTHER RESOURCES: Contact Us [ http://www.us-cert.gov/contact-us/ ] | Security Publications [ http://www.us-cert.gov/security-publications ] | Alerts and Tips [ http://www.us-cert.gov/ncas ] | Related Resources [ http://www.us-cert.gov/related-resources ] STAY CONNECTED: Sign up for email updates [ http://public.govdelivery.com/accounts/USDHSUSCERT/subscriber/new ]
Current thread:
- Reports of D-Link Router Backdoor US-CERT (Oct 18)