Executive brief
The D-Link DWR-932B is a portable LTE router used to provide wireless internet access. A security flaw in its web management component allows an unauthorized person to read sensitive system files from the device over the network. This could lead to the exposure of configuration details or credentials, potentially compromising the security of the network and its users.
Technical details
A path traversal vulnerability (CWE-22) exists in the 'qmiweb' HTTP daemon of the D-Link DWR-932B router (specifically firmware revB 02.02eu). The component fails to properly sanitize input, allowing the use of '..%2f' (URL-encoded dot-dot-slash) sequences to escape the intended web directory. An unauthenticated attacker can exploit this over the network to read arbitrary files on the underlying Linux filesystem. This vulnerability was disclosed alongside several other critical issues for this device, including hardcoded credentials and a UDP-based backdoor. As of the advisory date, no official patches were available from the vendor.
Affected products
- D-Link DWR-932B firmware 02.02eu revB
Timeline
- 2016-09-28: disclosed: Initial public disclosure by researcher Pierre Kim
- 2017-01-30: advisory: NVD publication of CVE-2016-10184