Executive brief
The D-Link DWR-932B LTE router contains a hidden backdoor that allows anyone on the network to gain full control of the device. By sending a specific command to the router, an attacker can bypass all security and access the system's command line. This could lead to the theft of internet traffic, interception of sensitive data, or the use of the router as a foothold for further attacks on the home or office network.
Technical details
A backdoor exists within the '/bin/appmgr' program on the D-Link DWR-932B router. A background thread listens on UDP port 39889; if it receives the string 'HELODBG', it executes '/sbin/telnetd -l /bin/sh'. This action launches a Telnet server that provides an unauthenticated root shell to any network-reachable attacker. This vulnerability is part of a larger set of security issues identified in the device's firmware, including hardcoded credentials and weak WPS PIN generation. As of the advisory date, no official patches were provided by the vendor for this legacy device.
Affected products
- D-Link DWR-932B firmware 2.02EU (Revision B) and earlier
Timeline
- 2016-09-28: disclosed: Initial researcher disclosure by Pierre Kim
- 2017-01-30: advisory: NVD publication date