2

I just found some vulnerabilities (CVE's) on my device at an firmware version. If I apply the update is it enough to solve the problem?

It's about DIR-600.

Anders
  • 65,582
  • 24
  • 185
  • 221
  • 2
    Depends whether they have been patched in the firmware that you update with. You would have to ask the router manufacturer to find that out though. – Matthew May 25 '16 at 08:52
  • Even if you find a new firmware you should not always trust the claims of the manufacturer that the firmware fixes all known bugs. D-Link is one of several manufacturers with a very bad track record, see http://routersecurity.org/bugs.php – Steffen Ullrich May 25 '16 at 09:12

1 Answers1

1

In case of DIR-600 yes ... but that is not always right! In you case dir-600 was checked and re-checked because is an outdated router that was commonly available for everyone.

It really depend on the product and I strongly recomand to check the official CVE page of the device to see if the last firmware version has any cve.

Lucian Nitescu
  • 1,860
  • 1
  • 15
  • 31
  • Where did you get this information that some new(?) firmware should fix the bugs in DIR-600? The only information I can find is a firmware from 2009 and exploits from later. Also, D-Link is known to be very loose about security, just look at routersecurity.org. – Steffen Ullrich May 25 '16 at 09:07
  • Oh yeah ... only Hardware Revision B1, B2 and B5 have security fixies (http://www.dlink.com/uk/en/support/product/dir-600-wireless-n-150-home-router?revision=deu_revb1b2) and that's why I've remembered it like that.. :( – Lucian Nitescu May 25 '16 at 10:26
  • Given the history of vulnerabilities at D-Link I would not be sure that this actually fixes all vulnerabilities and does not introduce new ones. And like you said - it is restricted to specific revisions and it is unknown what the OP actually uses. – Steffen Ullrich May 25 '16 at 10:35
  • I can't remember witch hardware revision I have back home but I am sure they did something (I mean I've made my test on the device after the upgrade) but the downfall is that I experienced some low performance after the upgrade – Lucian Nitescu May 25 '16 at 11:22
  • does this model support openwrt? – Rui F Ribeiro May 25 '16 at 11:35
  • Only for B1, B2 & B3 Hardware Revision – Lucian Nitescu May 25 '16 at 13:42