Slashdot Mirror


Researcher Find D-Link DWR-932 Router Is 'Chock Full of Holes' (helpnetsecurity.com)

Reader JustAnotherOldGuy writes: Security researcher Pierre Kim has unearthed a bucketload of vulnerabilities in the LTE router/portable wireless hotspot D-Link DWR-932. Kim found the latest available firmware has these vulnerabilities: Two backdoor accounts with easy-to-guess passwords that can be used to bypass the HTTP authentication used to manage the router
-A default, hardcoded Wi-Fi Protected Setup (WPS) PIN, as well as a weak WPS PIN generation algorithm
- Multiple vulnerabilities in the HTTP daemon
- Hardcoded remote Firmware Over The Air credentials
- Lowered security in Universal Plug and Play, and more.
"At best, the vulnerabilities are due to incompetence; at worst, it is a deliberate act of security sabotage from the vendor," says Kim, and advises users to stop using the device until adequate fixes are provided.

2 of 70 comments (clear)

  1. There's Your Problem. by Anonymous Coward · · Score: 1, Insightful

    UPnP has no security.

    Only morons leave it enabled on Home routers.

  2. Don't buy a router unless you can install openwrt. by anwyn · · Score: 3, Insightful

    Where ever you look commercial routers are full of security vulnerabilities.