VYPR

Dwr 932b Firmware

Sign in to watch

by Dlink

CVEs (10)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2016-10182Cri0.689.80.49Jan 30, 2017An issue was discovered on the D-Link DWR-932B router. qmiweb allows command injection with ` characters.
CVE-2016-10178Cri0.659.80.22Jan 30, 2017An issue was discovered on the D-Link DWR-932B router. HELODBG on port 39889 (UDP) launches the "/sbin/telnetd -l /bin/sh" command.
CVE-2016-10177Cri0.659.80.20Jan 30, 2017An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with the password admin and root with the password 1234.
CVE-2016-10181Hig0.507.50.12Jan 30, 2017An issue was discovered on the D-Link DWR-932B router. qmiweb provides sensitive information for CfgType=get_homeCfg requests.
CVE-2016-10179Hig0.507.50.12Jan 30, 2017An issue was discovered on the D-Link DWR-932B router. There is a hardcoded WPS PIN of 28296607.
CVE-2016-10186Hig0.497.50.03Jan 30, 2017An issue was discovered on the D-Link DWR-932B router. /var/miniupnpd.conf has no deny rules.
CVE-2016-10185Hig0.497.50.03Jan 30, 2017An issue was discovered on the D-Link DWR-932B router. A secure_mode=no line exists in /var/miniupnpd.conf.
CVE-2016-10184Hig0.497.50.06Jan 30, 2017An issue was discovered on the D-Link DWR-932B router. qmiweb allows file reading with ..%2f traversal.
CVE-2016-10183Hig0.497.50.06Jan 30, 2017An issue was discovered on the D-Link DWR-932B router. qmiweb allows directory listing with ../ traversal.
CVE-2016-10180Hig0.497.50.04Jan 30, 2017An issue was discovered on the D-Link DWR-932B router. WPS PIN generation is based on srand(time(0)) seeding.