• November 01, 2024, 04:24:11 PM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: DIR-655 UPNP vulnerabilities - Will these ever get fixed?  (Read 12884 times)

digitoxin

  • Level 1 Member
  • *
  • Posts: 9
DIR-655 UPNP vulnerabilities - Will these ever get fixed?
« on: June 05, 2013, 01:44:49 AM »

Is D-Link ever planning on releasing a firmware update for the DIR-655 to fix the UPNP vulnerabilities on this router?  They have not updated their UPNP page since Jan 30, 2013.

http://www.dlink.com/us/en/technology/upnp

I have confirmed that this router is vulnerable by using Steve Gibson's ShieldsUp tool as http://www.grc.com.

Logged

digitoxin

  • Level 1 Member
  • *
  • Posts: 9
Re: DIR-655 UPNP vulnerabilities - Will these ever get fixed?
« Reply #1 on: June 06, 2013, 12:20:14 AM »

My DIR-655 is Hardware Version: B1   Firmware Version: 2.10NA.  I am located in the U.S.
Logged

gh15

  • Level 1 Member
  • *
  • Posts: 1
Re: DIR-655 UPNP vulnerabilities - Will these ever get fixed?
« Reply #2 on: June 20, 2013, 12:43:54 PM »

same specs as digitoxin and have the same question.
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: DIR-655 UPNP vulnerabilities - Will these ever get fixed?
« Reply #3 on: June 20, 2013, 12:46:40 PM »

Link>Welcome!
  • What Hardware version is your router? Look at sticker under router.
  • Link>What Firmware version is currently loaded? Found on routers web page under status.
  • What region are you located?

Internet Service Provider and Modem Configurations
  • What ISP Service do you have? Cable or DSL?
  • What ISP Modem Mfr. and model # do you have?


I have verified this on my Rev B and have forwarded my results on to D-Link. Please be patient while they review this. Thank you.
« Last Edit: June 26, 2013, 12:03:09 PM by FurryNutz »
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

monkeylove

  • Level 1 Member
  • *
  • Posts: 15
Re: DIR-655 UPNP vulnerabilities - Will these ever get fixed?
« Reply #4 on: July 25, 2013, 11:31:18 PM »

I also disabled UPnP for the same reasons, although I found out only after I downgraded the FW to 2.01 (I had problems with 2.05, which is the latest for hardware B1, SE Asia).

Edit: This I can't explain.

I found another site that can check for vulnerabilities:

http://upnp-check.rapid7.com/

and the router passed, i.e., no response to a discovery request.

I decided to enable UPnP and try again, and it passed. I went to GRC Shields Up, and it passed.

I booted the modem, router (with UPnP enabled), and PC, and tried again in both sites, and the router passed.
« Last Edit: July 26, 2013, 12:05:00 AM by monkeylove »
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: DIR-655 UPNP vulnerabilities - Will these ever get fixed?
« Reply #5 on: July 26, 2013, 07:03:52 AM »

Thank you for sharing. D-Link is aware of this this issue. Please be patient while they review the situation. If your in need of immediate help and need more information, please phone contact your regional D-Link support office and inquired with in.
« Last Edit: August 08, 2013, 11:42:39 AM by FurryNutz »
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

monkeylove

  • Level 1 Member
  • *
  • Posts: 15
Re: DIR-655 UPNP vulnerabilities - Will these ever get fixed?
« Reply #6 on: August 08, 2013, 11:48:17 AM »

Sorry, my mistake. The vulnerability still appears for my unit (FW is 2.01 HW B1 for SE Asia). I only found out after I rebooted the PC, router, and modem, and checked with the sites again an hour ago.

I'd like to try FW 2.05, but I experienced problems with that (every few hours, any device connected to my router could not access Facebook or Google), which is why I downgraded to 2.01.



Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: DIR-655 UPNP vulnerabilities - Will these ever get fixed?
« Reply #7 on: August 08, 2013, 12:01:43 PM »

I recommend that you review this and start a new thread to see if maybe we can help you figure out why v2.01 or v2.05 isn't working for you:
Router Troubleshooting Suggestions and Tips

You can copy and past this into a new thread and post your answers and results there if you like.



Sorry, my mistake. The vulnerability still appears for my unit (FW is 2.01 HW B1 for SE Asia). I only found out after I rebooted the PC, router, and modem, and checked with the sites again an hour ago.

I'd like to try FW 2.05, but I experienced problems with that (every few hours, any device connected to my router could not access Facebook or Google), which is why I downgraded to 2.01.




Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

digitoxin

  • Level 1 Member
  • *
  • Posts: 9
Re: DIR-655 UPNP vulnerabilities - Will these ever get fixed?
« Reply #8 on: August 13, 2013, 04:48:57 PM »

I have no faith in D-Link that they will fix this issue.  They will just let this router End-of-Life and move on.  I have always stood by D-Link and their products, but after the substandard quality of their recent firmware releases across their product lines, I will be looking elsewhere for my next router purchase.  I have already had to downgrade my DIR-655 to firmware 2.07NA because of serious Wi-Fi problems with the latest release.
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: DIR-655 UPNP vulnerabilities - Will these ever get fixed?
« Reply #9 on: August 13, 2013, 05:38:40 PM »

I presume that not all product lines exhibit this problem I can confirm that they don't.

I have had v2.10NA loaded on my 655 and haven't had any issues with the WiFi. There could be environment conditions contributing to your WiFi that you seemingly be experiencing. A little trouble shooting might help narrow it down.

I would do a bit more troubleshooting and see if the problem could be narrowed down. There can be many things that can contribute to WiFi experiences on any router.

If your that concerned about the security issues, then you should phone contact D-Link support. They are aware of the issue. I don't know when they will released the fix. The more they hear about the problem the more they will probably get it released. This why we can people to phone contact D-Link support so they get visibility with there users and customers. We can't do anything about it here in the forums as it needs to be coded and tested then released.

I will again forward this on to D-Link and see if I can get some information.

If your unwilling to wait or let others help you out then you'll need to seek other solutions.

This thread is now locked as there is no additional information at this time that is helping anyone out. I'll re-open the thread when and if D-Link gives some information.

Good Luck.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: DIR-655 UPNP vulnerabilities - Will these ever get fixed?
« Reply #10 on: August 14, 2013, 01:43:50 PM »

Any one care to try this and see if uPnP is fixed or not?
http://forums.dlink.com/index.php?topic=55233.0
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: DIR-655 UPNP vulnerabilities - Will these ever get fixed?
« Reply #11 on: August 18, 2013, 03:54:08 PM »

I can confirm that this issue has been fixed with v2.11NA:
http://forums.dlink.com/index.php?topic=55233.0
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.