The Graveyard - Products No Longer Supported > DIR-855

WPA2 "Key Reinstallation Attack" (VU#228519)

(1/2) > >>

Ted Lyngmo:
Hi!

I wonder what the status of the newly discovered WPA2 "Key Reinstallation Attack" vulnerability is in the DIR-855 (F/W 1.24EU):
https://www.bleepingcomputer.com/news/security/new-krack-attack-breaks-wpa2-wifi-protocol/
http://www.kb.cert.org/vuls/byvendor?searchview&Query=FIELD+Reference=228519&SearchOrder=4

There's nothing noted by D-Link here:
http://www.kb.cert.org/vuls/id/CHEU-AQNMZT

Best regards,
Ted Lyngmo

FurryNutz:
D-link is ware of the issue already. No information on when fixes are forth coming. I presume they are in the testing and planning stages of this. Please be patient.
If you need more help and information regarding this, I recommend that you phone contact your regional D-Link support office and ask for help and information regarding this. We find that phone contact has better immediate results over using email.
Let us know how it goes please.

http://forums.dlink.com/index.php?topic=56542.0

Ted Lyngmo:
I wrote to D-Link and asked about VU#228519:

--- Quote ---Does the absence of the DIR-855 on this list mean that it's not affected?
http://www.dlink.com/uk/en/support/support-news/2017/october/18/response-to-krack-wpa2-key-reinstallation-attack-security-vulnerability
--- End quote ---

The answer was very clear:

--- Quote ---Yes
--- End quote ---

 :) / Ted

FurryNutz:
That is a older model router, about 10 years now or so...There are others of that generation which either isn't effected or won't be fixed. The main issue is that the vulnerability is mostly effecting modes of Wireless bridge or Repeater mode on routers that support it and on client side HW like phones and etc.

Ted Lyngmo:

--- Quote from: FurryNutz on November 06, 2017, 11:06:13 AM ---There are others of that generation which either isn't effected or won't be fixed.
--- End quote ---
Yeah, so I was very happy to learn that it wasn't affected. :)

Navigation

[0] Message Index

[#] Next page

Go to full version