Executive brief
The D-Link DWR-932B router, a portable LTE hotspot, contains a security flaw in its web management interface. An attacker can exploit this to view files and list directories on the device that should be restricted. This could lead to the exposure of sensitive system information or configuration details, potentially compromising the privacy and security of the user's network.
Technical details
A path traversal vulnerability exists in the 'qmiweb' HTTP daemon of the D-Link DWR-932B router (specifically Rev. B). The component fails to properly sanitize input, allowing the use of '../' sequences to navigate outside of the intended web root directory. A remote, unauthenticated attacker can exploit this to perform directory listings and read arbitrary files on the filesystem. This vulnerability was disclosed alongside several other critical issues, including hardcoded credentials and backdoors, for which the vendor reportedly provided no patches at the time of disclosure.
Affected products
- D-Link DWR-932B Firmware 02.02EU (Rev. B) and earlier
Timeline
- 2016-09-28: disclosed: Initial researcher disclosure by Pierre Kim
- 2017-01-30: advisory: NVD publication date