D-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows attackers to log in to administrator accounts with empty passwords.
The HNAP1 interface (Home Network Administration Protocol) in the router firmware does not properly verify credentials during the login process. The vulnerability classified as CWE-306 (missing authentication for critical function) allows authentication with an empty password. An attacker remotely, without any privileges and without user interaction, can gain access to the administrator account.
An attacker gains full administrative access to the device, enabling takeover of the router, modification of network configuration, interception of network traffic, and potential use of the device as an entry point to the local network.
Apply patches available from the manufacturer according to the references. If an update is not available, consider disabling access to the HNAP1 interface from the WAN side and restricting access to the administration panel only to trusted hosts on the local network.
D-Link DIR-822+ in firmware version V1.0.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDlink Dir 822
HWDlinkall versionsDlink Dir 822 Firmware
OSDlink1.0.2
Related vulnerabilities
D-Link DIR-859: RCE jako root przez UPnP bez uwierzytelnienia
Command injection w D-Link DIR-822+ — zdalne wykonanie poleceń
Buffer overflow w D-Link DIR-822 przez protokół HNAP (SetClientInfo)
Command injection w D-Link DIR-818LW i DIR-822 przez parametr RemotePort
Command injection w D-Link DIR-822 przez parametr uplink (HNAP1)