Inyección de comandos en R95 de D-Link
Cybersecurity Classified by Officially
D-Link R95, revisión de hardware Ax y versión de firmware BE9500_1.00.16. D-Link continúa verificando si otras revisiones de hardware o versiones de firmware también están afectadas. D-Link ha publicado una vulnerabilidad de severidad crítica que, en caso de ser explotada, podría permitir a un atacante remoto con privilegios elevados ejecutar comandos no autorizados en el sistema operativo del router, acceder o modificar información, interrumpir el servicio o llegar a tomar el control del dispositivo. Se ha publicado una prueba de concepto para esta vulnerabilidad. D-Link continúa investigando la vulnerabilidad y no ha confirmado una versión de firmware que la corrija. Hasta que el fabricante proporcione una solución, se recomienda: utilizar la aplicación AQUILA PRO para comprobar periódicamente si existen actualizaciones; evitar que las interfaces de administración estén expuestas directamente a Internet; deshabilitar o restringir la administración remota cuando no sea necesaria; limitar el acceso administrativo a usuarios y equipos de confianza; utilizar contraseñas administrativas robustas y diferentes de las empleadas en otros servicios; restringir mediante cortafuegos el ac...
Read the original at the source: https://www.incibe.es/node/662581
Officially imported this from INCIBE’s own source. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
This publication has changed since it was first published
2 versions recorded. The original is kept in full — nothing is overwritten.
- v2 imported change on current
- v1 as first published on
Provenance
- Organization
- INCIBE — imported from official source
- Official source
- https://www.incibe.es/rss.xml RSS
- Imported
- September 24, 2026 11:30
- Versions
- 2 recorded
- Identity
662581 at https://www.incibe.es