Executive brief
The D-Link DWR-932B LTE router contains undocumented administrative accounts with simple, hard-coded passwords. An attacker can use these credentials to remotely log into the device, granting them full control over the network traffic and device settings. This could lead to the interception of sensitive data, unauthorized network access, or complete disruption of internet services for the user.
Technical details
The D-Link DWR-932B router (specifically Revision B) contains multiple hard-coded credential sets for undocumented TELNET and SSH services. The 'admin' account uses the password 'admin', and the 'root' account uses the password '1234'. These services are enabled by default in the firmware and are accessible over the network. An attacker can exploit this by connecting to the device via SSH or Telnet to gain a root-level shell. Additionally, the device contains a 'magic string' backdoor where sending 'HELODBG' via UDP to port 39889 triggers an unauthenticated root telnet session. No patch is currently available as the vendor has not addressed these legacy vulnerabilities.
Affected products
- D-Link DWR-932B Firmware revB 2.02.EU and prior
Timeline
- 2016-09-28: disclosed: Initial discovery and write-up by security researcher Pierre Kim
- 2017-01-30: advisory: CVE published in the National Vulnerability Database (NVD)