Security flaw could allow attackers to take control of D-Link routers

Security flaw could allow attackers to take control of D-Link routers
Have you checked yours?

A backdoor security vulnerability has been discovered in several D-Link routers that could allow an attacker to take control of devices and spy on users' browsing activity.

The issue was discovered and reported by Craig Heffner, a vulnerability researcher with Tactical Network Solutions, who writes in a blog post that an attacker could gain remote access to a router when using a string of letters in the right order.

Heffner, who discovered the flaw hidden deep within D-Link's firmware code, writes: "If your browser's user agent string is 'xmlset_roodkcableoj28840ybtide' (no quotes), you can access the web interface without any authentication and view/change the device settings."

Heffner says affected models likely include D-Link's DIR-100, DI-524, DI-524UP, DI-604S, DI-604UP, DI-604+, TM-G5240 and the DIR-615. He also points out that Planex Communication's BRL-04UR and BRL-04CW models may be affected as they appear to use the same firmware.

Updated firmware

D-Link has responded to the claim in a note on its website, writing: "We are proactively working with the sources of these reports as well as continuing to review across the complete product line to ensure that the vulnerabilities discovered are addressed.

"We will continue to update this page to include the relevant product firmware updates addressing these concern."

The company added that users should check that their wireless network is secure, disable remote access to the router if not required (this is the default setting) and ignore unsolicited emails related to security vulnerabilities.

Kane Fulton
Kane has been fascinated by the endless possibilities of computers since first getting his hands on an Amiga 500+ back in 1991. These days he mostly lives in realm of VR, where he's working his way into the world Paddleball rankings in Rec Room.
Latest in Security
Google Chrome dark mode
Google updates Chrome extension rules to ban affiliate link injection without user action or benefit
Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard
This worrying botnet targets unsecure TP-Link routers - thousands of devices already hacked
Avast cybersecurity
UK cybersecurity sector could be worth £13bn, research shows
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
Trump
Hackers are abusing $TRUMP tokens to lure victims in to new phishing scam
An American flag flying outside the US Capitol building against a blue sky
Sean Plankey selected as CISA director by President Trump
Latest in News
Two Android phones on a green and blue background showing Google Messages
Struggling with slow Google Messages photo transfers? Google says new update will make 'noticeable difference'
Elayne, Egwene, and Nynaeve dressed regally and on horseback in The Wheel of Time season 3
'There's a reason why we do it': The Wheel of Time showrunner responds to fans who are still upset over the Prime Video show's plot alterations
Google Pixel 9
Android 16 could bring an improved Samsung DeX-style desktop mode to more phones
An Nvidia GeForce RTX 4060 Ti
Nvidia could unleash RTX 5060 and 5060 Ti GPUs on PC gamers tomorrow, but there’s no sign of rumored RTX 5050 yet
AI writing
ChatGPT just wrote the most beautiful short story, and I wonder what I'm even doing here
Google Chrome dark mode
Google updates Chrome extension rules to ban affiliate link injection without user action or benefit