Junglewise Threat Intelligence

CVE-2016-10178: D-Link DWR-932B unauthenticated backdoor in appmgr

CVE-2016-10178 · Severity: critical · CVSS 9.8 · Published 2017-01-30

Technologies: Dlink Dwr-932b Firmware, Dlink Dwr-932b. Vendors: Dlink, D-Link.

Executive brief

The D-Link DWR-932B LTE router contains a hidden backdoor that allows anyone on the network to gain full control of the device. By sending a specific command to the router, an attacker can bypass all security and access the system's command line. This could lead to the theft of internet traffic, interception of sensitive data, or the use of the router as a foothold for further attacks on the home or office network.

Technical details

A backdoor exists within the '/bin/appmgr' program on the D-Link DWR-932B router. A background thread listens on UDP port 39889; if it receives the string 'HELODBG', it executes '/sbin/telnetd -l /bin/sh'. This action launches a Telnet server that provides an unauthenticated root shell to any network-reachable attacker. This vulnerability is part of a larger set of security issues identified in the device's firmware, including hardcoded credentials and weak WPS PIN generation. As of the advisory date, no official patches were provided by the vendor for this legacy device.

Affected products

  • D-Link DWR-932B firmware 2.02EU (Revision B) and earlier

Timeline

  • 2016-09-28: disclosed: Initial researcher disclosure by Pierre Kim
  • 2017-01-30: advisory: NVD publication date

References

Related threats