• October 21, 2018, 07:12:57 PM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: DIR-880L FW v1.08 Build 06 Beta - Official Security Release - WW Region!  (Read 1937 times)

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 46019
  • D-Link Global Forum Moderator
    • New DIR-890L Router with SmartConnect™ Technology

Firmware:   v1.08 Build 06   02/28/2018   WW Region!
Revision Info:   
Problems Resolved:
Reported: 01/14/2018
Discovered by: Kaixiang Zhang of Qihoo 360 Gear Team

CVE-2018-6527 - XSS vulnerability in htdocs/webinc/js/adv_parent_ctrl_map.php allowing remote attackers to read a cookie via a crafted deviceid parameter to soap.cgi.

CVE-2018-6528 - XSS vulnerability in htdocs/webinc/body/bsc_sms_send.php allowing remote attackers to read a cookie via a crafted receiver parameter to soap.cgi

CVE-2018-6529 - XSS vulnerability in htdocs/webinc/js/bsc_sms_inbox.php allowing remote attackers to read a cookie via a crafted Treturn parameter to soap.cgi.

CVE-2018-6530 - OS command injection vulnerability in soap.cgi (soapcgi_main incgibin) allowing remote attackers to execute arbitrary OS commands via the service parameter.


Enhancements:
1. None

NOTE: if your DIR-880L router is working with out any issues, it's recommended to keep the current version of FW that is loaded unless your are effected by one of the fixes. Use at your own risk.

IF IT WORKS, DON'T FIX IT!!!  ::)
Get it here:
NA Region:
DIR-880L

Follow the >FW Update Process
« Last Edit: February 28, 2018, 02:04:18 PM by GreenBay42 »
Logged
"Nothing Funny about It...." We are not here to Impress anyone! You have a be a COMPETENT user first to under stand COMPETENT help!