Junglewise Threat Intelligence

CVE-2016-10183: D-Link DWR-932B directory traversal in qmiweb

CVE-2016-10183 · Severity: high · CVSS 7.5 · Published 2017-01-30

Technologies: Dlink Dwr-932b Firmware, Dlink Dwr-932b. Vendors: D-Link, Dlink.

Executive brief

The D-Link DWR-932B router, a portable LTE hotspot, contains a security flaw in its web management interface. An attacker can exploit this to view files and list directories on the device that should be restricted. This could lead to the exposure of sensitive system information or configuration details, potentially compromising the privacy and security of the user's network.

Technical details

A path traversal vulnerability exists in the 'qmiweb' HTTP daemon of the D-Link DWR-932B router (specifically Rev. B). The component fails to properly sanitize input, allowing the use of '../' sequences to navigate outside of the intended web root directory. A remote, unauthenticated attacker can exploit this to perform directory listings and read arbitrary files on the filesystem. This vulnerability was disclosed alongside several other critical issues, including hardcoded credentials and backdoors, for which the vendor reportedly provided no patches at the time of disclosure.

Affected products

  • D-Link DWR-932B Firmware 02.02EU (Rev. B) and earlier

Timeline

  • 2016-09-28: disclosed: Initial researcher disclosure by Pierre Kim
  • 2017-01-30: advisory: NVD publication date

References

Related threats