cbcvebase.
CVE-2016-10177
published 2017-01-30

CVE-2016-10177: An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with the password admin and root with the…

PriorityP261critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
6.93%
93.4th percentile
An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with the password admin and root with the password 1234.

Affected

1 ranges
VendorProductVersion rangeFixed in
dlinkdwr-932b_firmware

Detection & IOCsextracted from sources · hover to see the quote

otheradmin:admin (TELNET/SSH login)
otherroot:1234 (TELNET/SSH login)
port23 (TELNET)
port22 (SSH)
  • Detect authentication attempts to TELNET (port 23) or SSH (port 22) on D-Link DWR-932B devices using the hardcoded credentials admin/admin or root/1234.
  • Flag any successful TELNET or SSH session to a D-Link DWR-932B router as these services are undocumented and should not be exposed; their presence indicates a backdoor.
  • ·The backdoor credentials are hardcoded in the D-Link DWR-932B firmware; the TELNET and SSH services are undocumented and not user-configurable, meaning they cannot be disabled through normal administrative interfaces.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.