Overview
Belkin N600 DB Wireless Dual Band N+ router, model F9K1102 v2 with firmware version 2.10.17 and possibly earlier, contains multiple vulnerabilities.
Description
CWE-330: Use of Insufficiently Random Values - CVE-2015-5987 DNS queries originating from the Belkin N600, such as those to resolve the names of firmware update and NTP servers, use predictable TXIDs that start at 0x0002 and increase incrementally. An attacker with the ability to spoof DNS responses can cause the router to contact incorrect or malicious hosts under the attacker's control. |
Impact
A remote, unauthenticated attacker may be able to spoof DNS responses to cause vulnerable devices to contact attacker-controlled hosts or induce an authenticated user into making an unintentional request to the web server that will be treated as an authentic request. A LAN-based attacker can bypass authentication to take complete control of vulnerable devices. |
Solution
Apply an update |
Restrict access and use strong passwords |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 6.8 | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Temporal | 6.1 | E:POC/RL:U/RC:C |
Environmental | 4.6 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
- http://www.belkin.com/us/support-search?search=f9k1102v2
- http://www.belkin.com/us/support-article?articleNum=4868
- https://cwe.mitre.org/data/definitions/330.html
- https://cwe.mitre.org/data/definitions/319.html
- https://cwe.mitre.org/data/definitions/255.html
- https://cwe.mitre.org/data/definitions/603.html
- https://cwe.mitre.org/data/definitions/352.html
Acknowledgements
These vulnerabilities were reported by Joel Land of the CERT/CC.
This document was written by Joel Land.
Other Information
CVE IDs: | CVE-2015-5987, CVE-2015-5988, CVE-2015-5989, CVE-2015-5990 |
Date Public: | 2015-08-31 |
Date First Published: | 2015-08-31 |
Date Last Updated: | 2016-09-22 19:48 UTC |
Document Revision: | 35 |