Blog | G5 Cyber Security

D-Link blunder: Firmware encryption key exposed in unencrypted image

Security researchers have demonstrated a method to decrypt proprietary firmware images embedded in D-Link routers. The same technique has been used earlier this month by another security researcher. The researchers deciphered the encryption of the latest 1.11B02 firmware version of the router. The decryption and encryption keys were found embedded in the unencrypted firmware binary that they could then extract and analyze for stored decryption keys. An older version was also found to be decrypted using Binwalk, a program called /bin/imgdecrypt, which is the decryption tool.

Source: https://www.bleepingcomputer.com/news/security/d-link-blunder-firmware-encryption-key-exposed-in-unencrypted-image/

Exit mobile version