First published: Mon Jan 30 2017(Updated: )
An issue was discovered on the D-Link DWR-932B router. /var/miniupnpd.conf has no deny rules.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link DWR-932B Firmware | =02.02eu-revb | |
D-Link DWR-932B | ||
All of | ||
D-Link DWR-932B Firmware | =02.02eu-revb | |
D-Link DWR-932B |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-10186 is classified as high due to the absence of deny rules in the miniupnpd configuration file.
To fix CVE-2016-10186, update the D-Link DWR-932B router firmware to a version that includes appropriate deny rules.
Users of D-Link DWR-932B firmware version 02.02eu-revb are affected by CVE-2016-10186.
If exploited, CVE-2016-10186 could allow unauthorized access to the network due to misconfigured upstream settings.
A potential workaround for CVE-2016-10186 is to manually configure the router settings to restrict unwanted traffic until a firmware update is available.