Advisory Details

May 15th, 2023

D-Link DIR-2150 HNAP Incorrect Implementation of Authentication Algorithm Authentication Bypass Vulnerability

ZDI-23-628
ZDI-CAN-20910

CVE ID CVE-2023-34282
CVSS SCORE 8.8, AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AFFECTED VENDORS D-Link
AFFECTED PRODUCTS DIR-2150
VULNERABILITY DETAILS

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-2150 routers. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the SOAP API interface, which listens on TCP port 80 by default. A crafted authentication header can cause authentication to succeed without providing proper credentials. An attacker can leverage this vulnerability to bypass authentication on the system.

ADDITIONAL DETAILS

Fixed in Firmware v1.06
https://support.dlink.com.au/Download/download.aspx?product=DIR-2150


DISCLOSURE TIMELINE
  • 2023-04-28 - Vulnerability reported to vendor
  • 2023-05-15 - Coordinated public release of advisory
  • 2023-06-02 - Advisory Updated
CREDIT Anonymous
BACK TO ADVISORIES