• February 23, 2025, 01:48:55 AM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: Security Vulnerability - D-Link DCS-93xL model family allows unrestricted upload  (Read 4802 times)

peterd

  • Level 1 Member
  • *
  • Posts: 20

In case you haven't heard...

http://www.kb.cert.org/vuls/id/377348

D-Link has a firmware update available for the affected version.
Logged

acellier

  • Level 4 Member
  • ****
  • Posts: 417

The linked article cites the vulnerability in firmware v1.04, used on hardware v1, then strangely says "According to D-Link's security advisory, users should update the firmware for affected device to version 2.0.17-b62"
... which would only be for hardware v2, right?
Logged

peterd

  • Level 1 Member
  • *
  • Posts: 20

I did find that odd too....  D-Link's site actually has firmware downloads for hardware revision A and B:

http://support.dlink.com/ProductInfo.aspx?m=DCS-932L
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting

Rev B FW is not backwards compatible with Rev A HW.

The vulnerability is for v1.04 and prior version of FW. Anything past v1.04 should be now safe. The article is incorrect on it's statement about upgrading to v2.0x for Rev A cameras.

v1.10 just came out last week for Rev A
v2.01 just came out last week for Rev B for those users with Rev B cameras.

I recommend that you phone contact your regional D-Link support office and ask for help and information regarding this. We find that phone contact has better immediate results over using email.
Let us know how it goes please.
« Last Edit: March 16, 2015, 01:03:12 PM by FurryNutz »
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

acellier

  • Level 4 Member
  • ****
  • Posts: 417

I submitted comments to the CERT site.
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting

Looks like it's been updated.  ;)
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

RYAT3

  • Level 10 Member
  • *****
  • Posts: 2254

Upload to what exactly? SD card? Or OS?
Logged