Hidden Factory Backdoor in D-Link Wireless Routers Enables Unauthenticated LAN Telnet Access

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2024-6045?

CVE-2024-6045 is a vulnerability classified as Hidden Functionality and Use of Hard-coded Credentials, affecting G403 (affected versions: earlier – < 1.10.01), G415 (affected versions: earlier – < 1.10.01), G416 (affected versions: earlier – < 1.10.01), and 12 more products. This vulnerability is rated High, with a CVSS score of 8.8. Current sources do not report this vulnerability as exploited.

Overview

Original source data

Certain models of D-Link wireless routers contain an undisclosed factory testing backdoor. Unauthenticated attackers on the local area network can force the device to enable Telnet service by accessing a specific URL and can log in by using the administrator credentials obtained from analyzing the firmware.

Affected products and scope

The normalized record identifies the following versions as affected and sets the default status to unaffected:

  • G403, G415, G416, M18, R03, R04, R12, R18: versions earlier than 1.10.01.
  • E30, M30, M32, M60, R32: versions earlier than 1.10.02.
  • E15, R15: versions earlier than 1.20.01.

TWCERT and the D-Link advisory also list M15 as affected, although it is absent from the normalized affected_products list. D-Link lists M15 across all hardware revisions, including /2 and /3 kits, with fixed firmware 1.20.01 and 1.21.01 for the corresponding branches identified in the advisory.

The D-Link advisory covers models in the EAGLE PRO AI Family and AQUILA PRO AI Family, with its model table distinguishing worldwide and non-US scope. Confirm the device's actual region and hardware revision rather than relying only on the model name. The status of parallel branches or versions not explicitly covered by the sources remains unverified.

Technical details

The root cause is a combination of two related weaknesses: hidden functionality left in production firmware, covered by CWE-912, and hard-coded administrator credentials, covered by CWE-798.

At a high level, the attack sequence is:

  1. The attacker has access to the device's local area network but does not need prior authentication.
  2. The attacker accesses a specific URL handled by the device to force Telnet to be enabled.
  3. The attacker logs in to Telnet with administrator credentials obtained by analyzing the firmware.

The vendor describes this as LAN-side unauthenticated access to management features. The specific URL, implementation location in the firmware, and credential values are not disclosed in the reviewed material. The sources do not fully describe the actions available after successful administrator login.

Exploitability

The vulnerability is reachable from the router's local area network or adjacent network. The attacker does not need an existing account, user interaction is not required, and the supplied assessment describes the attack as low complexity.

The source-level sequence is access to a specific URL to enable Telnet, followed by login with administrator credentials obtained through firmware analysis. The URL, credential values, and command sequence are not needed to establish the exposure and are not reproduced here.

The supplied record marks public_exploit as false and known_exploited as null. A CISA enrichment returned during research recorded exploitation as none at the time of that record, but that time-scoped status does not establish current or future exploitation activity.

Technical impact

The confirmed technical outcome is that the device can be forced to enable Telnet and can accept a login using administrator credentials without prior authentication. This gives an attacker who is already on the LAN access to router management functions.

Possible consequences include access to sensitive device or configuration information, unauthorized configuration changes, and disruption of router operation. The supplied assessment indicates that confidentiality, integrity, and availability can all be affected, but the sources do not describe the complete set of actions available after login.

The directly established impact is to the affected router. The sources do not confirm that the flaw automatically compromises other devices on the network or provides access beyond the router's management authority.

Business impact

Routers commonly control traffic, separate networks, and provide management functions for other devices. This flaw could let a person already present on the LAN reach administrative functions without authentication, change network configuration, or disrupt service.

The exact post-login capabilities depend on the functions available on each model, but the sources confirm login using administrator credentials. Organizations should therefore prioritize routers protecting internal networks, guest networks, or IoT devices. The reviewed sources do not provide evidence that any particular organization or device has been compromised.

Remediation

  1. Update firmware for the correct model and device branch:
  • G403, G415, G416, M18, R03, R04, R12, R18: update to fixed firmware 1.10.01.
  • E30, M30, M32, M60, R32: update to fixed firmware 1.10.02.
  • E15, R15: update to fixed firmware 1.20.01.
  • M15: D-Link lists fixed firmware 1.20.01 and 1.21.01 for the corresponding branches. Select the firmware that matches the device's hardware revision and branch.
  1. Check the D-Link Device Mobile application for the automatic forced update or trigger the update manually. If the automatic update fails, the D-Link advisory directs owners to download the appropriate patched update and upload it through the device web GUI.

  2. After updating, verify the firmware version shown in the product interface and compare it with the intended fixed firmware. Check the hardware revision on the device label or in the interface before selecting firmware.

  3. Until updating is possible, restrict untrusted devices from reaching the router's LAN and management plane where the network architecture permits. This is temporary containment, not a replacement for the fixed firmware.

  4. Do not rely only on changing the normal administrator password, because the issue involves hidden functionality and hard-coded credentials. Installing the appropriate fixed firmware remains the primary remediation.

Detection

  1. Inventory D-Link devices matching the models in the affected summary, then check the model, hardware revision, distribution region, and firmware shown in the management interface or D-Link application.
  2. Compare the installed firmware with the model-specific fixed boundaries in the remediation section. Do not infer that an unlisted model or parallel branch is safe.
  3. Check whether Telnet is enabled unexpectedly and review the device configuration for unusual management changes. This is a precautionary review signal, not a vendor-confirmed IOC.
  4. Check update status in the D-Link Device Mobile application and verify the displayed firmware version in the device interface after updating.

The reviewed sources do not provide a specific log event, log path, or IOC. The absence of suspicious log evidence does not prove that the device was not exploited.

Sources (17)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan