alexzir
15.06.2020, 12:36
D-Link выпустил обновление прошивки, закрывающее 3 из 6 известных проблем безопасности для DIR-865L wireless router. Один патч из критически важных, остальные имеют рейтинг высокой важности.
Атакующие могли использовать закрытые уязвимости для удаленного управления, скрытого сбора информации, загрузки malware или удаления информации.
Список известных уязвимостей из National Vulnerability Database (NVD):
CVE-2020-13782 (https://nvd.nist.gov/vuln/detail/CVE-2020-13782): Improper Neutralization of Special Elements Used in a Command (Command Injection) - critical-severity score 9.8, not fixed
CVE-2020-13786 (https://nvd.nist.gov/vuln/detail/CVE-2020-13786): Cross-Site Request Forgery (CSRF) - high-severity score 8.8, fixed
CVE-2020-13785 (https://nvd.nist.gov/vuln/detail/CVE-2020-13785): Inadequate Encryption Strength - high-severity score 7.5, fixed
CVE-2020-13784 (https://nvd.nist.gov/vuln/detail/CVE-2020-13784): Predictable seed in pseudo-random number generator - high-severity score 7.5 not fixed
CVE-2020-13783 (https://nvd.nist.gov/vuln/detail/CVE-2020-13783): Cleartext storage of sensitive information - high-severity score 7.5, fixed
CVE-2020-13787 (https://nvd.nist.gov/vuln/detail/CVE-2020-13787): Cleartext transmission of sensitive information - high-severity score 7.5, not fixed
Источник: https://www.bleepingcomputer.com/ne...evere-security-bugs-in-home-router-unpatched/ (https://www.bleepingcomputer.com/news/security/d-link-leaves-severe-security-bugs-in-home-router-unpatched/)
Атакующие могли использовать закрытые уязвимости для удаленного управления, скрытого сбора информации, загрузки malware или удаления информации.
Список известных уязвимостей из National Vulnerability Database (NVD):
CVE-2020-13782 (https://nvd.nist.gov/vuln/detail/CVE-2020-13782): Improper Neutralization of Special Elements Used in a Command (Command Injection) - critical-severity score 9.8, not fixed
CVE-2020-13786 (https://nvd.nist.gov/vuln/detail/CVE-2020-13786): Cross-Site Request Forgery (CSRF) - high-severity score 8.8, fixed
CVE-2020-13785 (https://nvd.nist.gov/vuln/detail/CVE-2020-13785): Inadequate Encryption Strength - high-severity score 7.5, fixed
CVE-2020-13784 (https://nvd.nist.gov/vuln/detail/CVE-2020-13784): Predictable seed in pseudo-random number generator - high-severity score 7.5 not fixed
CVE-2020-13783 (https://nvd.nist.gov/vuln/detail/CVE-2020-13783): Cleartext storage of sensitive information - high-severity score 7.5, fixed
CVE-2020-13787 (https://nvd.nist.gov/vuln/detail/CVE-2020-13787): Cleartext transmission of sensitive information - high-severity score 7.5, not fixed
Источник: https://www.bleepingcomputer.com/ne...evere-security-bugs-in-home-router-unpatched/ (https://www.bleepingcomputer.com/news/security/d-link-leaves-severe-security-bugs-in-home-router-unpatched/)