ID

VAR-E-201502-0354


TITLE

Multiple D-Link and TRENDnet Routers 'ncc/ncc2' Service Multiple Security Vulnerabilities

Trust: 0.3

sources: BID: 72816

DESCRIPTION

Multiple D-Link and TRENDnet routers are prone to a local unauthenticated vulnerability, a remote unauthenticated vulnerability and a cross-site request-forgery vulnerability.
An attacker can exploit this issue to perform certain unauthorized actions and gain unauthorized root access to an affected device. Successful exploits will result in the complete compromise of an affected device.
Following products are vulnerable:
D-Link DIR-820L (Rev A) 1.02B10, DIR-820L (Rev A) 1.05B03, and DIR-820L (Rev B) 2.01b02
TRENDnet TEW-731BR (Rev 2) 2.01b01

Trust: 0.3

sources: BID: 72816

AFFECTED PRODUCTS

vendor:trendnetmodel:tew-731br (rev 2.01b01scope:eqversion:2)

Trust: 0.3

vendor:d linkmodel:dir-820l 2.01b02scope: - version: -

Trust: 0.3

vendor:d linkmodel:dir-820l 1.05b03scope: - version: -

Trust: 0.3

vendor:d linkmodel:dir-820l 1.02b10scope: - version: -

Trust: 0.3

vendor:trendnetmodel:tew-731br (rev 2.02b01scope:neversion:2)

Trust: 0.3

sources: BID: 72816

EXPLOIT

An attacker can exploit this issue using readily available tools and by gaining physical access to the device.
The researcher who discovered these issues has created a proof-of-concept. Please see the references for more information

Trust: 0.3

sources: BID: 72816

PRICE

Free

Trust: 0.3

sources: BID: 72816

TYPE

Design Error

Trust: 0.3

sources: BID: 72816

CREDITS

Peter Adkins

Trust: 0.3

sources: BID: 72816

EXTERNAL IDS

db:BIDid:72816

Trust: 0.3

sources: BID: 72816

REFERENCES

url:http://seclists.org/bugtraq/2015/feb/164

Trust: 0.3

url:http://www.dlink.com/

Trust: 0.3

url:http://www.trendnet.com/

Trust: 0.3

sources: BID: 72816

SOURCES

db:BIDid:72816

LAST UPDATE DATE

2022-07-27T09:49:38.490000+00:00


SOURCES UPDATE DATE

db:BIDid:72816date:2015-02-26T00:00:00

SOURCES RELEASE DATE

db:BIDid:72816date:2015-02-26T00:00:00