Digital Defense, Inc. Discloses Zero-Day Vulnerabilities in D-Link VPN Routers

By Fortra's Digital Defense

 

Work From Home Use of Popular VPN Routers Increases Immediacy of Critical Patch

SAN ANTONIO, TexasDecember 8, 2020 – Digital Defense, Inc., a leader in vulnerability management and threat assessment solutions, today announced that its Vulnerability Research Team (VRT) uncovered a previously undisclosed vulnerability affecting D-Link VPN routers. D-Link DSR-150, DSR-250, DSR-500 and DSR-1000AC VPN routers running firmware version 3.14 and 3.17 are vulnerable to a remotely exploitable root command injection flaw.

These devices are commonly available on consumer websites/ecommerce sites such as Amazon, Best Buy, Office Depot and Walmart. Given the rise in work-from-home due to the pandemic, more employees may be connecting to corporate networks using one of the affected devices.

The vulnerable component of these devices is accessible without authentication. From both WAN and LAN interfaces, this vulnerability could be exploited over the Internet. Consequently, a remote, unauthenticated attacker with access to the router’s web interface could execute arbitrary commands as root, effectively gaining complete control of the router. With this access, an attacker could intercept and/or modify traffic, cause denial of service conditions and launch further attacks on other assets. D-Link routers can connect up to 15 other devices simultaneously.

“Our standard practice is to work in tandem with organizations on a coordinated disclosure effort to facilitate a prompt resolution to a vulnerability. The Digital Defense VRT reached out to D-Link who worked diligently on a patch. We will continue outreach to customers ensuring they are aware and able to take action to mitigate any potential risk introduced by the vulnerability,” states Mike Cotton, senior vice president of engineering at Digital Defense.

D-Link is a global leader in designing and developing networking and connectivity products for consumers, small businesses, medium to large-sized enterprises and service providers. Since 1986, the company has grown into an award-winning global brand with over 2,000 employees in 60 countries. D-Link’s line of VPN routers enable remote workers to connect securely to company resources.

What You Can Do

D-Link’s recent advisory provides more details about the updates that have been released, which should be applied: https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10195​. For additional information, customers should contact D-Link directly.

Digital Defense Research Methodology and Practices

The Digital Defense VRT regularly works with organizations promoting the responsible disclosure of zero-day vulnerabilities. The expertise of the VRT, when coupled with the company’s next generation hybrid cloud platform, Fortra Vulnerability Management, enables early detection capabilities. When zero-days are discovered and internally validated, the VRT immediately contacts the affected vendor to notify the organization of the new finding(s) and assists, where possible, with the vendor’s remediation actions.

To view Digital Defense’s zero-day advisories to date, please visit: https://www.digitaldefense.com/vulnerability-research/

About Digital Defense

Our SaaS platform supports Fortra Vulnerability Management, Web Application Scanning, and Active Threat Sweep that together provide:

  • Asset discovery and tracking
  • OS and web application risk assessment
  • Targeted malware threat assessment
  • Machine learning features that leverage threat intelligence
  • Agentless & agent-based scanning
  • Penetration testing for networks, mobile applications, and web applications
  • Compliance management. One of the world’s longest tenured PCI-Approved Scanning Vendors

Our SaaS platform virtually eliminates false-positives associated with legacy vulnerability management solutions, while also automating the tracking of dynamic and transient assets and prioritizing results based on business criticality.

Share This