Executive brief
The D-Link DWR-932B LTE router contains a configuration error that disables security checks for the UPnP service. This service is typically used to allow devices on a network to automatically discover each other and open ports. Because security mode is disabled, an attacker could potentially manipulate network settings or redirect traffic without authorization, compromising the integrity of the local network.
Technical details
An issue was discovered in the D-Link DWR-932B router where the UPnP daemon (miniupnpd) is configured with 'secure_mode=no' in /var/miniupnpd.conf. By default, UPnP 'secure mode' restricts UPnP forwarded ports to the IP address of the device requesting the mapping. With this security feature disabled, the router may allow UPnP requests to map ports to any internal IP address, potentially allowing a remote attacker to bypass firewall restrictions or perform unauthorized port forwarding. This vulnerability is part of a larger set of security issues identified in this device, including hardcoded credentials and backdoors.
Affected products
- D-Link DWR-932B firmware 02.02EU revB
Timeline
- 2016-09-28: disclosed: Initial researcher disclosure by Pierre Kim
- 2017-01-30: advisory: NVD publication date