92,000 D-Link NAS devices have a back port
- April 8, 2024
- 0
At least 92,000 legacy D-Link NAS devices contain a hard-coded backdoor that allows attackers to break in. A patch does not exist. A security researcher has discovered a
At least 92,000 legacy D-Link NAS devices contain a hard-coded backdoor that allows attackers to break in. A patch does not exist. A security researcher has discovered a
At least 92,000 legacy D-Link NAS devices contain a hard-coded backdoor that allows attackers to break in. A patch does not exist.
A security researcher has discovered a dangerous flaw in D-Link NAS devices. The vulnerability consists of an injection flaw combined with a hardcoded account (Message bus, without password). The bug and account allow hackers to run their own code on the NAS.
The good news is that D-Link no longer makes NAS devices today and the vulnerable devices are many years old. The bad news is that D-Link no longer supports the affected storage servers, but at least 92,000 vulnerable devices are still in use.
The following software is vulnerable to the error:
D-Link does not intend to continue the divested NAS business. So users don’t have to wait for a patch. This is not surprising: for example, the vulnerable D-Link Sharecenter 2-Bay-BAS DNS-325 was withdrawn from circulation in 2015 and has not been supported since 2017.
The best solution is to finally send these vulnerable devices into a well-deserved retirement and replace them with an up-to-date solution. That being said, it’s not a good idea to make a NAS available directly over the Internet without additional protection. Especially in this case, data is easy prey for attackers.
Source: IT Daily
As an experienced journalist and author, Mary has been reporting on the latest news and trends for over 5 years. With a passion for uncovering the stories behind the headlines, Mary has earned a reputation as a trusted voice in the world of journalism. Her writing style is insightful, engaging and thought-provoking, as she takes a deep dive into the most pressing issues of our time.