• D-Link fixes serious security flaws that could have left your bus

    From TechnologyDaily@1337:1/100 to All on Sun May 28 12:00:04 2023
    D-Link fixes serious security flaws that could have left your business wide open to attack

    Date:
    Sun, 28 May 2023 10:44:44 +0000

    Description:
    Two severe flaws in D-View network management suite allowed for remote code execution..

    FULL STORY ======================================================================

    D-Link has released patches for two critical vulnerabilities found in its network management suite which could allow threat actors to bypass authentication and execute arbitrary code, remotely.

    The company fixed two flaws found in D-View, its network management suite
    that various businesses use for general network management and
    administration.

    The flaws were discovered late last year by security researchers taking part in Trend Micros Zero Day Initiative (ZDI).During the event, researchers found multiple vulnerabilities, with two standing out: CVE-2023-32165, and CVE-2023-32169. The former is a remote code execution flaw, which could be used to run malicious code with SYSTEM privileges. The latter, on the other hand, is an authentication bypass vulnerability that allows for the
    escalation of privilege, unauthorized access of information, and in some cases, installation of malware. Beta patch

    Both flaws carry a severity score of 9.8 (critical).The issue affects D-View
    8 version 2.9.1.27 and older. D-Link released the patch roughly two weeks
    ago, and is now urging users to apply it as soon as possible.

    "As soon as D-Link was made aware of the reported security issues, we had promptly started our investigation and began developing security patches,"
    the company said in a security advisory. The vendor also warned users that
    the patch is actually beta software or hot-fix release, meaning additional changes might occur in the future. It also means that the D-View might be unstable, or crash, after the introduction of the patch.

    The vendor also told users to verify the hardware revision of their endpoints , by inspecting the underside label or the web configuration panel, so that they dont download the wrong firmware update.

    The full list of the discovered vulnerabilities is as follows: Read more

    This venerable security vulnerability has exposed millions of routers to
    attack


    Pretty much all Wi-Fi routers are vulnerable to attack, study finds


    These are the best ID theft protection tools right now ZDI-CAN-19496:
    D-Link D-View TftpSendFileThread Directory Traversal Information Disclosure Vulnerability ZDI-CAN-19497: D-Link D-View TftpReceiveFileHandler Directory Traversal Remote Code Execution Vulnerability ZDI-CAN-19527: D-Link D-View uploadFile Directory Traversal Arbitrary File Creation Vulnerability ZDI-CAN-19529: D-Link D-View uploadMib Directory Traversal Arbitrary File Creation or Deletion Vulnerability ZDI-CAN-19534: D-Link D-View showUser Improper Authorization Privilege Escalation ZDI-CAN-19659: D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability Here's
    our list of the best firewalls right now

    Via: BleepingComputer



    ======================================================================
    Link to news story: https://www.techradar.com/news/d-link-fixes-serious-security-flaws-that-could- have-left-your-business-wide-open-to-attack


    --- Mystic BBS v1.12 A47 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)