Pubblicato firmware DIR-880L Ax 1.21 build 01 20200518.
DIR-880L Firmware Release Notes
Firmware: 1.21B01 Hotfix
Hardware: Ax
Date: May 18, 2020
Problems Resolved:
- CVE-2019-15126 - KrØØk vulnerability
Brief:
An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause
internal errors (related to state transitions) in a WLAN device that lead to improper layer 2 Wi-Fi encryption with
a consequent possibility of information disclosure over the air for a discrete set of traffic, a different
vulnerability than CVE-2019-9500, CVE-2019-9501, CVE-2019-9502, and CVE-2019-9503.
The vulnerability affects both WPA2-Personal and WPA2-Enterprise protocols, with AES-CCMP encryption.
NVD: https://nvd.nist.gov/vuln/detail/CVE-2019-15126
CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15126
___________________________________________________________________________________________________________________
DISCLAIMER: Please note that this is a device beta software, beta firmware, or hot-fix release which is still
undergoing final testing before its official release. The beta software, beta firmware, or hot-fix is provided on
an “as is” and “as available” basis and the user assumes all risk and liability for use thereof. D-Link does not
provide any warranties, whether express or implied, as to the suitability or usability of the beta firmware. D-Link
will not be liable for any loss, whether such loss is direct, indirect, special or consequential, suffered by any
party as a result of their use of the beta firmware.
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10162
https://eu.dlink.com/it/it/support/support-news/2020/may/11/krook-industry-wide-vulnerability