Executive brief
A security vulnerability exists in the D-Link DIR-878 A1 router, a device used to provide wireless internet connectivity for homes and small offices. An attacker can exploit this flaw to take control of the router without needing a password or physical access. This could allow an unauthorized user to disrupt internet service, intercept network traffic, or use the device as a foothold for further attacks on the local network.
Technical details
An unauthenticated command injection vulnerability exists in the 'SetDMZSettings' functionality of the D-Link DIR-878 A1 router (firmware FW101B04.bin). The vulnerability stems from improper sanitization of the 'IPAddress' parameter in prog.cgi, which is stored in NVRAM as 'dmz_ipaddr'. This value is subsequently retrieved by librcm.so and used to construct iptables shell commands via snprintf() before being executed by twsystem(). A remote, unauthenticated attacker can exploit this by sending a specially crafted HTTP request containing shell metacharacters in the IPAddress field, leading to arbitrary code execution with elevated privileges.
Affected products
- D-Link DIR-878 A1 FW101B04.bin
Timeline
- 2025-11-13: disclosed
- 2025-11-13: advisory