Executive brief
The D-Link DWR-932B LTE router contains a hardcoded Wi-Fi Protected Setup (WPS) PIN. This allows anyone within wireless range of the device to easily connect to the Wi-Fi network without knowing the actual password. Once connected, an unauthorized user could monitor network traffic or access other devices on the local network.
Technical details
A hardcoded WPS PIN vulnerability exists in the D-Link DWR-932B (Revision B) router. The PIN '28296607' is hardcoded within the /bin/appmgr binary and is used by the HostAP configuration by default. An attacker within wireless range can use this static PIN to bypass Wi-Fi authentication and join the network. Additionally, the router's algorithm for generating alternative PINs relies on a weak seed (system time), making them susceptible to brute-force attacks. As of the advisory date, no official patch was provided by the vendor.
Affected products
- D-Link DWR-932B Rev. B (Firmware 02.02EU)
Timeline
- 2016-09-28: disclosed: Initial researcher disclosure by Pierre Kim
- 2017-01-30: advisory: NVD publication date