US-CERT is aware of reports that the firmware for various D-Link routers contains a backdoor that allows unauthenticated remote users to bypass the routers' password authentication mechanism. An unauthenticated remote attacker can take any action as an administrator using the remote management web server.
D-Link is maintaining a page to inform users of this issue and provide updates as patches are released.
For more information, please see Vulnerability Note VU#248083.
Please share your thoughts.
We recently updated our anonymous product survey; we'd welcome your feedback.