D-Link Forums

D-Link Network Video Recorders => DNR-202L => Topic started by: GreenBay42 on November 22, 2017, 09:00:59 AM

Title: DNR-202L - Firmware Security Patch v2.05.01 Released
Post by: GreenBay42 on November 22, 2017, 09:00:59 AM
A firmware patch has been released.

Firmware --> ftp://FTP2.DLINK.COM/SECURITY_ADVISEMENTS/DNR-202L/REVA/DNR-202L_REVA_FIRMWARE_PATCH_v2.05.01.zip (ftp://FTP2.DLINK.COM/SECURITY_ADVISEMENTS/DNR-202L/REVA/DNR-202L_REVA_FIRMWARE_PATCH_v2.05.01.zip)

Release Notes:

Vulnerability ID: CVE-2012-5958   

Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka libupnp, formerly the Intel SDK for UPnP devices) before 1.6.18 allows remote attackers to execute arbitrary code via a UDP packet with a crafted string that is not properly handled after a certain pointer subtraction.
Title: Re: DNR-202L - Firmware Security Patch v2.05.01 Released
Post by: nukemedic on December 23, 2017, 07:15:34 AM
Glad to hear that security is being maintained. 

But I noticed that the button and tab descriptions all seem incorrect now - looks like variable names are being used instead of labels?
Title: Re: DNR-202L - Firmware Security Patch v2.05.01 Released
Post by: FurryNutz on December 23, 2017, 10:26:07 AM
Please give a example of what your seeing or screen capture please.
Adding Screenshots In A Post (http://forums.dlink.com/index.php?topic=58120.0)

What browser are you using?

Glad to hear that security is being maintained. 

But I noticed that the button and tab descriptions all seem incorrect now - looks like variable names are being used instead of labels?
Title: Re: DNR-202L - Firmware Security Patch v2.05.01 Released
Post by: nukemedic on December 24, 2017, 04:36:40 AM
latest safari on mac running sierra (not high sierra yet)

this is the first page, all pages are like this, settings pages even worse

(http://preview.ibb.co/kBS39m/Untitled.jpg)
Title: Re: DNR-202L - Firmware Security Patch v2.05.01 Released
Post by: FurryNutz on December 24, 2017, 10:46:50 AM
Ok, I can confirm this as well:
(https://image.ibb.co/cyq4X6/Screen_Shot_2017_12_24_at_11_37_10_AM.png) (https://ibb.co/myxUzm)

Grammer Check:
(https://image.ibb.co/dqJDQR/Screen_Shot_2017_12_24_at_11_38_54_AM.png) (https://ibb.co/bJif5R)

Seen in both Safari and FF ESR (v52)

I'll pass this one to D-Link for review.

Title: Re: DNR-202L - Firmware Security Patch v2.05.01 Released
Post by: RYAT3 on December 30, 2017, 02:04:50 PM
Are your months there?

https://www.screencast.com/t/lAqGr2xzx (https://www.screencast.com/t/lAqGr2xzx)
Title: Re: DNR-202L - Firmware Security Patch v2.05.01 Released
Post by: FurryNutz on December 30, 2017, 02:11:02 PM
There are a few UI issues i've found. I've passed this long to D-Link for review. I presume they will have a look at this Monday.

If you need too, you could revert back to v2.04. I presume this issue will take some time before we see a fixed release.  ::)

Are your months there?

https://www.screencast.com/t/lAqGr2xzx (https://www.screencast.com/t/lAqGr2xzx)
Title: Re: DNR-202L - Firmware Security Patch v2.05.01 Released
Post by: RYAT3 on December 30, 2017, 04:04:30 PM
There are a few UI issues i've found. I've passed this long to D-Link for review. I presume they will have a look at this Monday.

If you need too, you could revert back to v2.04. I presume this issue will take some time before we see a fixed release.  ::)

Are your months there?

https://www.screencast.com/t/lAqGr2xzx (https://www.screencast.com/t/lAqGr2xzx)

2.04.03 is where it started for me.

I'm curious on your mac, specifically:  Are your months missing in playback?

Have you tried to reinstall 2.05?
Title: Re: DNR-202L - Firmware Security Patch v2.05.01 Released
Post by: FurryNutz on January 02, 2018, 10:08:35 AM
Looks like this issue was reproduced at D-Link and is now under review for fix. Hopefully soon. Please be patient.  ;)
Title: Re: DNR-202L - Firmware Security Patch v2.05.01 Released
Post by: magarity on August 17, 2018, 05:55:24 PM
I've been using this patch for a while now and it works without any problem except the UI has all this goofy sample text instead of real menu values such as "System Restart Btn" for reset after setting change button.  Pretty much all the menu items are labeled in Java style camelCase. I can figure them out since I do software development but to release this to customers like this is kind of sad. Please polish it off and release an official update since this patch isn't even what comes up when going through the DLink website's "find updates".
Title: Re: DNR-202L - Firmware Security Patch v2.05.01 Released
Post by: GreenBay42 on August 27, 2018, 02:58:17 PM
Sorry 10 days later....

Is this in the DNR-202L UI or mydlink.com?

What browser(s) are you using? 

We installed the 2.05 firmware and the web UI is OK in IE11. Going to test other browsers later today.

Also, BETA firmware are not pushed through the mydlink server.
Title: Re: DNR-202L - Firmware Security Patch v2.05.01 Released
Post by: wifilink on September 05, 2018, 04:46:38 PM
Why isn't this firmware update on the D-Link support page for this product? It is still showing version 2.04.03

http://support.dlink.ca/ProductInfo.aspx?m=DNR-202L (http://support.dlink.ca/ProductInfo.aspx?m=DNR-202L)
Title: Re: DNR-202L - Firmware Security Patch v2.05.01 Released
Post by: FurryNutz on September 05, 2018, 04:48:08 PM
You'll need to contact D-Link Canada about that. The update file listed here is for the USA. However is available for use for Canadian users to try.
USA and Canada handle there own files and support sites.

Why isn't this firmware update on the D-Link support page for this product? It is still showing version 2.04.03

http://support.dlink.ca/ProductInfo.aspx?m=DNR-202L (http://support.dlink.ca/ProductInfo.aspx?m=DNR-202L)
Title: Re: DNR-202L - Firmware Security Patch v2.05.01 Released
Post by: GreenBay42 on September 05, 2018, 05:37:52 PM
D-Link Canada discontinued this product a while ago but should be posting security firmware (unless they found issues with it and removed it). I will contact them tomorrow morning.
Title: Re: DNR-202L - Firmware Security Patch v2.05.01 Released
Post by: FurryNutz on September 05, 2018, 05:38:46 PM
Thank you Sir.  ;)
Title: Re: DNR-202L - Firmware Security Patch v2.05.01 Released
Post by: GreenBay42 on September 06, 2018, 07:01:25 AM
I notified Canada and they will post sometime today.
Title: Re: DNR-202L - Firmware Security Patch v2.05.01 Released
Post by: magarity on January 02, 2019, 04:13:49 PM
When will the 2.05 update get polished up? It works but the menu texts are all default programming stuff and hard to decipher.
Title: Re: DNR-202L - Firmware Security Patch v2.05.01 Released
Post by: GreenBay42 on January 03, 2019, 06:48:41 AM
They have been working on a new firmware to fix a certificate issue but not sure when it is getting released. The original date was 2 months ago but it got delayed. I really hope the GUI fixes are included. I will post as soon as it is released.
Title: Re: DNR-202L - Firmware Security Patch v2.05.01 Released
Post by: FurryNutz on January 03, 2019, 12:12:53 PM
Is there any way you check to see if the UI problems were fixed in the forth coming update?

They have been working on a new firmware to fix a certificate issue but not sure when it is getting released. The original date was 2 months ago but it got delayed. I really hope the GUI fixes are included. I will post as soon as it is released.
Title: Re: DNR-202L - Firmware Security Patch v2.05.01 Released
Post by: GreenBay42 on January 03, 2019, 01:58:03 PM
No way for me to check.
Title: Re: DNR-202L - Firmware Security Patch v2.05.01 Released
Post by: FurryNutz on January 03, 2019, 02:00:28 PM
Will be patient a bit more I guess.  ::)
Title: Re: DNR-202L - Firmware Security Patch v2.05.01 Released
Post by: FurryNutz on February 22, 2019, 11:35:36 AM
Wanna give this a try?  ;)
http://forums.dlink.com/index.php?topic=74589.0 (http://forums.dlink.com/index.php?topic=74589.0)
When will the 2.05 update get polished up? It works but the menu texts are all default programming stuff and hard to decipher.
Title: Re: DNR-202L - Firmware Security Patch v2.05.01 Released
Post by: FurryNutz on February 22, 2019, 11:36:15 AM
http://forums.dlink.com/index.php?topic=74589.0 (http://forums.dlink.com/index.php?topic=74589.0)

Why isn't this firmware update on the D-Link support page for this product? It is still showing version 2.04.03

http://support.dlink.ca/ProductInfo.aspx?m=DNR-202L (http://support.dlink.ca/ProductInfo.aspx?m=DNR-202L)
Title: Re: DNR-202L - Firmware Security Patch v2.05.01 Released
Post by: FurryNutz on February 22, 2019, 11:37:19 AM
http://forums.dlink.com/index.php?topic=74589.0 (http://forums.dlink.com/index.php?topic=74589.0)

latest safari on mac running sierra (not high sierra yet)

this is the first page, all pages are like this, settings pages even worse

(http://preview.ibb.co/kBS39m/Untitled.jpg)
Title: Re: DNR-202L - Firmware Security Patch v2.05.01 Released
Post by: magarity on May 05, 2019, 11:12:16 AM
Does anyone know how to repurpose this hardware? It almost certainly is using some flavor of Linux. It'd be great to have instructions on how to install. The utter lack of support for the device from DLink has me ready to move on.
Title: Re: DNR-202L - Firmware Security Patch v2.05.01 Released
Post by: FurryNutz on May 05, 2019, 11:21:06 AM
Haven't seen any one mentioning this for this unit. I presume the HW and FW are all proprietary to D-Link. Most DNRs and DNS for D-Link are proprietary.
It is what it does. Works for me and my 3 cameras which this unit will be going full time online capturing data.