vendor:
DSL-2640B
by:
Todor Donev
7.5
CVSS
HIGH
Unauthenticated Remote DNS Change
200
CWE
Product Name: DSL-2640B
Affected Version From: EU_2.03
Affected Version To: EU_2.03
Patch Exists: YES
Related CWE: N/A
CPE: h:d-link:dsl-2640b
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
D-Link DSL-2640B Unauthenticated Remote DNS Change Exploit
Different D-Link Routers are vulnerable to DNS change. The vulnerability exist in the web interface, which is accessible without authentication. Tested firmware version: EU_2.03. Once modified, systems use foreign DNS servers, which are usually set up by cybercriminals. Users with vulnerable systems or devices who try to access certain sites are instead redirected to possibly malicious sites. Modifying systems' DNS settings allows cybercriminals to perform malicious activities like steering unknowing users to bad sites, replacing ads on legitimate sites, controlling and redirecting network traffic, and pushing additional malware.
Mitigation:
Users should ensure that their routers are running the latest firmware version and that they have enabled the router's firewall. Additionally, users should ensure that they are using a secure DNS server.