D-Link Forums

The Graveyard - Products No Longer Supported => Access Points / Extenders => DAP-1522 => Topic started by: DavePDX on January 11, 2012, 09:07:45 AM

Title: Regarding firmware ver. 1.40 WPS fix
Post by: DavePDX on January 11, 2012, 09:07:45 AM
Does the firmware fix in version 1.40 described as "Fixed: WPS issue." address the issue indicated in the Wi-Fi Protected Setup (WPS) issue listed in this message?
http://forums.dlink.com/index.php?topic=45200.0 (http://forums.dlink.com/index.php?topic=45200.0)
The firmware (ver. 1.40) was posted on 1/5/2012 and the message about the security vulnerability was posted on 1/7/2012.

The "Fixed: WPS issue" description could refer to something as innocuous as a spelling error. I can't assume, because of the sequence of the dates, that version 1.40 fixes the WPS security issue. Any clarification would be helpful.
Title: Re: Regarding firmware ver. 1.40 WPS fix
Post by: FurryNutz on January 11, 2012, 09:53:08 AM
I don't believe v1.40 addresses the security vulnerability found. That is currently being addresses with several other Mfrs including D-Link. Any fixes will probably be mentioned a future FW release and say something along the lines of "fixed WPS security vulnerability". The vulnerability found is a protocol standard that has to be addressed at higher levels possibly as most Mfr use the WPS standard that was developed by others, so they are probably at the forefront on figuring out a fix, then pass it to the mfrs.
Title: Re: Regarding firmware ver. 1.40 WPS fix
Post by: DavePDX on January 11, 2012, 10:08:23 AM
The timing of the two (the firmware with WPS fix and the WPS security warning) was nothing other than a coincidence then. But my simple mind was confused! <grin> Thanks for your help.
Title: Re: Regarding firmware ver. 1.40 WPS fix
Post by: FurryNutz on January 11, 2012, 10:12:20 AM
Well if you want to test it out you could see if you can hack in when your WPS is ON and OFF. The WPS vulnerability was just found and made official last month. So I presume it might take some time to get everyone involved and find the fix, then implement it for each Mfr, test it and after passing, release it. I can't say when that all will occur however I might guess probably with in 6 mths possibly depending on the severity of it. We'll all find out when it happens though.
Title: Re: Regarding firmware ver. 1.40 WPS fix
Post by: DavePDX on January 11, 2012, 11:12:23 AM
I disabled the WPS a few days ago on my two DAP-1522's (one is an access point, the other a bridge). I'll just leave them set that way until I read about an official fix. My hacking skills aren't now what they once were. Thanks again for your help.
Title: Re: Regarding firmware ver. 1.40 WPS fix
Post by: FurryNutz on January 11, 2012, 11:19:53 AM
 ;)