D-Link and TRENDnet 'ncc2' service – multiple vulnerabilities

Posted by Peter Adkins on Mar 02

Discovered by:
—-
Peter Adkins <peter.adkins () kernelpicnic net>

Access:
—-
Local network; unauthenticated access.
Remote network; unauthenticated access*.
Remote network; ‘drive-by’ via CSRF.

Tracking and identifiers:
—-
CVE – Mitre contacted; not yet allocated.

Platforms / Firmware confirmed affected:
—-
D-Link DIR-820L (Rev A) – v1.02B10
D-Link DIR-820L (Rev A) – v1.05B03
D-Link DIR-820L (Rev B) – v2.01b02
TRENDnet…

Leave a Reply