Junglewise Threat Intelligence

CVE-2016-10182: D-Link DWR-932B command injection in qmiweb

CVE-2016-10182 · Severity: critical · CVSS 9.8 · Published 2017-01-30

Technologies: Dlink Dwr-932b Firmware, Dlink Dwr-932b. Vendors: Dlink, D-Link.

Executive brief

The D-Link DWR-932B is a portable LTE router used to provide mobile internet access. A security flaw in its web management component allows an attacker to take complete control of the device. This could lead to the interception of user traffic, unauthorized access to the local network, or the device being used as a foothold for further attacks.

Technical details

A command injection vulnerability exists in the 'qmiweb' HTTP daemon of the D-Link DWR-932B router (specifically revision B). The issue stems from improper neutralization of special characters, specifically backticks (`), within web requests. An unauthenticated remote attacker can exploit this to execute arbitrary shell commands with the privileges of the web server. This vulnerability is part of a larger set of security issues identified in this device, including hardcoded credentials and a UDP-based backdoor. No official patch was released by the vendor at the time of disclosure, and the device was reported to be end-of-life or unmaintained.

Affected products

  • D-Link DWR-932B firmware 2.02EU

Timeline

  • 2016-09-28: disclosed: Initial researcher disclosure by Pierre Kim
  • 2017-01-30: advisory: NVD publication date

References

Related threats