Enlarge your botnet with: top D-Link...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

In this article, we are going to discuss vulnerabilities detected in the top D-Link routers: * DIR890L * DIR885L * DIR895L * and other DIR8xx D-Link routers cruising for a bruising. The devices use the same code, thus giving a magnificent and quite tempting opportunity to attackers to add them to a botnet. Moreover, we have managed to make Mirai for the devices by modifying its compilation script a bit. We will also say a couple of words about our interaction with the developer (which has brought no results, while the vulnerabilities are still not closed). Two vulnerabilities are related to the cgibin - the main CGI file that generates web interface pages to control the router. The other vulnerability deals with system recovery. ## Stealing login and password ### One HTTP request - login/password is in your bag. The first detected vulnerability lies in phpcgi. Phpcgi is a symlink to cgibin and is responsible for processing requests to .php, .asp and .txt pages. It parses data sent...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息