Executive brief
The D-Link DWR-932B LTE router contains a configuration error in its UPnP service. This flaw allows unauthorized network traffic to bypass intended security restrictions because the device lacks rules to deny potentially malicious requests. An attacker could exploit this to manipulate network settings or gain unauthorized access to services behind the router.
Technical details
The D-Link DWR-932B router (specifically Revision B) contains a vulnerability in its UPnP implementation. The configuration file /var/miniupnpd.conf is missing 'deny' rules, which are typically used to restrict which devices or IP ranges can utilize UPnP to modify NAT/firewall rules. An attacker on the network can exploit this lack of access control to perform unauthorized port mapping or other UPnP-related actions. This issue is part of a larger set of vulnerabilities identified in this specific hardware revision, including hardcoded credentials and backdoors. No official patch was released as the vendor reportedly ceased support for this model revision.
Affected products
- D-Link DWR-932B firmware 02.02EU (Rev. B) and earlier
Timeline
- 2016-09-28: disclosed: Initial public disclosure by security researcher Pierre Kim
- 2017-01-30: advisory: NVD publication date