Уровень 0 · материалов: 8
В кластер входят документы об уязвимостях и бэкдорах в сетевом оборудовании (роутеры, системы видеонаблюдения), но не включают уязвимости операционных систем.
Общие признаки: критические уязвимости безопасности, удаленное выполнение кода, бэкдоры в прошивках, маршрутизаторы и сетевые устройства, несанкционированный доступ с правами root
Группа выше: Безопасность IoT и встраиваемых устройств
Смысл: The main idea is the revelation of a critical security backdoor in various D-Link routers that allows unauthorized administrative access via a specific User-Agent string, illustrating systemic security failures in the manufacturer's firmware.
A reverse engineer discovered a backdoor in D-Link routers that grants full admin access if a specific User-Agent string is used.
Смысл: The main idea is that specific D-Link routers contain a firmware backdoor that allows root access via Telnet using a predictable password based on the firmware version, reflecting poorly on D-Link's security standards.
A security researcher discovered a root-access backdoor in several D-Link router models caused by an open Telnet port and predictable firmware-based passwords.
Смысл: The main idea is that certain popular router models (specifically D-Link DSL 2640NRU) have a critical security flaw where multiple devices share a common default WPS PIN, allowing for nearly instantaneous unauthorized access.
The author discovers that many D-Link DSL 2640NRU routers share a common WPS PIN, allowing Wi-Fi passwords to be cracked in seconds using Reaver.
Смысл: The text highlights the incompetence of D-Link's security response, showing how a patch intended to fix critical vulnerabilities was poorly implemented, introduced new bugs, and left administrative functions exposed.
Reverse engineering reveals that D-Link's security patch for DIR-890L routers was ineffective, introduced new vulnerabilities, and failed to block unauthenticated administrative access.
Смысл: The main idea is to alert the community about a critical security backdoor in certain TP-Link routers that allows remote code execution with root privileges via HTTP and TFTP, as well as potential CSRF vulnerabilities.
A security researcher found a backdoor in TP-Link routers (TL-WDR4300, TL-WR743ND) allowing root access via a specific HTTP request and TFTP file download.
Смысл: The text describes a critical security flaw (a backdoor) in widespread surveillance equipment software that allows unauthorized remote root access via a flawed authentication process on a specific network port.
A critical 0-day backdoor in Xiaongmai-based surveillance devices allows remote root access via a reverse-engineered challenge-response mechanism on port 9530.
Смысл: The main idea is to warn users and administrators about widespread critical vulnerabilities in the UPnP and SSDP protocols used by most major router manufacturers, which could lead to remote unauthorized code execution.
Critical zero-day vulnerabilities in UPnP SDKs expose millions of routers and smart devices from vendors like Cisco, Asus, and TP-Link to remote attacks.
Смысл: The text highlights the dangers of poor network segmentation and insecure firmware in ISP-provided hardware, demonstrating how a lack of basic security can lead to massive data leaks and unauthorized service usage.
A security researcher exposed critical vulnerabilities in Beeline's wired internet infrastructure that allowed unauthorized access to user data and free internet access via firmware flaws.