Using a D-Link Wireless Router? You Could Be at Risk of Hacking

D-Link Wireless Router Vulnerability Exposes Users to DNS Hijacking Risks

Recent reports highlight a significant vulnerability in several popular models of DSL wireless routers produced by D-Link that could enable remote attackers to manipulate DNS settings. This flaw may allow cybercriminals to hijack user traffic, redirecting it from legitimate websites to malicious sites under their control.

The primary purpose of DNS hijacking is to stealthily redirect users from authentic sites to fraudulent ones, which may deceive users into disclosing personal data. This vulnerability is not exclusive to the D-Link routers, as the underlying software flaw is present in a widely utilized firmware called ZynOS, developed by ZyXEL Communications Corporation, and implemented in devices from various manufacturers including TP-Link and ZTE.

The issue was brought to light by Bulgarian security researcher Todor Donev, who identified the shortfall in D-Link’s widely used DSL2740R model, among others, particularly the DLS-320B. The risk associated with this vulnerability extends beyond D-Link devices, potentially affecting a broad spectrum of routers that operate on the same firmware, exposing countless homes and businesses to the threat of DNS hijacking.

In a related context, a similar vulnerability discovered last year involved the RomPager web server from AllegroSoft. This flaw rendered approximately 12 million routers, modems, and other network devices across various manufacturers vulnerable to attacks aimed at DNS hijacking, impacting brands such as Edimax, Huawei, and ZyXEL.

The newly identified flaw permits attackers to expose internal web servers of affected routers to the public internet. This exposure increases the likelihood of exploitation, facilitating unauthorized access to the router’s administrative interface. By successfully altering the DNS settings, attackers can execute a range of malicious activities. These may include redirecting users to phishing sites masquerading as legitimate pages, replacing legitimate ads on websites with harmful content, obstructing critical system updates, and even pushing malware directly onto compromised devices.

To exploit the router vulnerability, a malicious actor would need either access to the router’s network or for the router to be publicly viewable. However, even within local networks, hackers could employ techniques such as Cross-Site Request Forgery (CSRF) to send targeted HTTP requests to the router’s IP address, potentially allowing them to manipulate its configurations.

Donev publicized the details of this vulnerability without prior notification to the affected manufacturers and has released a proof-of-concept exploit specifically targeting the D-Link DSL-2740R router. Although this model has been discontinued, it remains in support, leaving its users at risk if they do not implement adequate security measures.

This incident exemplifies key MITRE ATT&CK tactics that may have been employed during this cyber attack, such as initial access via external exploitation, privilege escalation through unauthorized configurations, and persistence through continuous access to affected devices. As businesses increasingly rely on interconnected technology, the importance of securing networking hardware cannot be overstated. Organizations should prioritize patching vulnerabilities and ensuring robust security protocols are in place to mitigate such risks.

Source link