D-Link Forums

Announcements => Security Advisories => Topic started by: GreenBay42 on March 09, 2018, 07:58:09 AM

Title: DNR-2020-4P Firmware v1.02.04 - BETA Release
Post by: GreenBay42 on March 09, 2018, 07:58:09 AM
Note: This product is not supported in the US.

Version 1.02.04 released to fix a security issue:

Firmware --> ftp://FTP2.DLINK.COM/SECURITY_ADVISEMENTS/DNR-2020-04P/REVA/DNR-2020-04P_REVA_FIRMWARE_v1.02.04.zip (ftp://FTP2.DLINK.COM/SECURITY_ADVISEMENTS/DNR-2020-04P/REVA/DNR-2020-04P_REVA_FIRMWARE_v1.02.04.zip)


Release Notes:

Discovered on 2/3/2018 - Davide Quarta ( @_ocean )

Problems Resolved:
The admin account password can be retrieved by a malicious user by accessing the /config/nvrroutine URI and de-obfuscating the password.