Junglewise Threat Intelligence

CVE-2016-10181: D-Link DWR-932B information disclosure in qmiweb

CVE-2016-10181 · Severity: high · CVSS 7.5 · Published 2017-01-30

Technologies: Dlink Dwr-932b Firmware, Dlink Dwr-932b. Vendors: Dlink, D-Link.

Executive brief

The D-Link DWR-932B router contains a security flaw that allows unauthorized users to access sensitive configuration data. This router is commonly used to provide internet access via LTE mobile networks. An attacker could exploit this to gain private information about the device's setup, potentially compromising the security of the network it provides.

Technical details

An information disclosure vulnerability exists in the D-Link DWR-932B router within the 'qmiweb' HTTP daemon. The component fails to properly restrict access to sensitive data when handling 'CfgType=get_homeCfg' requests. An unauthenticated remote attacker can send a specially crafted HTTP request to the device to retrieve sensitive configuration information, including potentially the WPS PIN and other system settings. This issue is part of a broader set of vulnerabilities identified in the device's firmware (revB 2.02EU), which also includes hardcoded credentials and backdoors. No official patch was provided by the vendor at the time of disclosure.

Affected products

  • D-Link DWR-932B Firmware 02.02EU Rev. B

Timeline

  • 2016-09-28: disclosed: Initial researcher disclosure by Pierre Kim
  • 2017-01-30: advisory: NVD publication date

References

Related threats