Pubblicato firmware DIR-890L Ax 1.20 build 01 20170927.
N.B. Occorre aggiornare prima alla versione di transizione DIR-890L Ax 1.11 build 04 20170925 contenuta nel pacchetto.
Nota edizione EU
DIR-890L Firmware Release Notes
Firmware: FW v1.11b04
Hardware: Rev. A1
Release Date: 2017/10/3
Note:
1. The firmware v1.11b04 is the transitional version for upgrading to v1.20b01 or later version.
2. Below is the procedure for firmware upgrade:
• Connect to the router via LAN port or WIRELESS interface.
• Log in to the D-Link management page (http://192.168.0.1 or http://dlinkrouter.local./)
• Go to the firmware upgrade page, upload the firmware v1.11b04 and wait for the device to reboot.
• Log in to the D-Link management page again.
• Go to the firmware upgrade page and check the button of online firmware check and download the firmware v1.20b01 or later version.
• Upload the firmware v1.20b01
• Wait for the device to reboot and don’t power off the router during the firmware upgrade.
• The router is fully upgraded. For the detailed information, please refer to the firmware release note of v1.20b01.
DIR-890L Firmware Release Notes
Firmware: FW v1.20b01
Hardware: Rev. A1
Release Date: 2017/10/3
Note:
1. The firmware version is advanced to v1.20
2. The firmware v1.20b01 must be upgraded from the transitional version of firmware v1.11b04.
Problems Resolved:
1. Fixed the security issues reported by Embedi.com on Sep 12th ,2017.
Issue 1) Command Injection in http://192.168.0.1/getcfg.php
Issue 2) Stack overflow HNAP in http://192.168.0.1/HNAP1/
Issue 3) Command Injection for “EXEC REBOOT SYSTEM” command for service jcpd.
Nota edizione DE cumulativa
DIR-890L Rev.A Release Note
Firmware: FW 1.20b01
Release Date: 2017/10/3
Note:
1. The firmware version is advanced to v1.20
2. The firmware v1.20b01 must be upgraded from the transitional version of firmware v1.11b04.
Problems Resolved:
1. Fixed the security issues reported by Embedi.com on Sep 12th ,2017.
Issue 1: Command Injection in http://192.168.0.1/getcfg.php
Issue 2: Stack overflow HNAP in http://192.168.0.1/HNAP1/
Issue 3: Command Injection for “EXEC REBOOT SYSTEM” command for service jcpd.
---------------------------
Firmware: FW 1.11b04
Release Date: 2017/10/3
Note:
1. The firmware v1.11b04 is the transitional version for upgrading to v1.20b01 or later version.
---------------------------
Firmware: 1.11b02_gbii
Date: 2016/11/18
Changes:
1. Fix internet connection issue when WAN type is Dynamic IP and WAN subnet mask is 255.255.255.255
---------------------------
Firmware: 1.11b01_g97i
Date: 2016/09/07
Changes:
1. Fix HNAP Service Stack-Based Buffer Overflow Vulnerability
CWE-121 CVE-2016-6563 VU#677427
http://www.kb.cert.org/vuls/id/677427
---------------------------
Firmware: 1.10b07
Date: 2016/05/24
Enchancement:
1. USB performance enhancement.
2. WiFi stability enhancement.
3. iQoS supporting.
4. VLAN support for internet access.
5. IPv6 6in4 improved.
---------------------------
Firmware: 1.10b02-02_g37i
Date: 2016/03/07
Changes:
1. Fix DHCP Reservation and Parental Corntrol.
Max number of DHCP Reservation rules = 24
Max number of Paretal Corntrol rules = 24
---------------------------
Firmware: 1.10b02
Date: 2016/02/04
Changes:
1. Mix Microsoft Edge issue.
Enchancement:
1. New QoS Setup
2. Add WPS-PBC on/off function. Default is on.
3. Add WPS-PIN lock/unlock function. Lock is off - Unlock is on. Default is off.
---------------------------
Firmware: DIR890A1_FW108b04.bin
Date: 2015/07/14
Changes:
1. Solve the issue that the client number would become zero in client information sometimes.
2. Mobile phone Samsung S6 Internet slow [HQ20150702000007]
3. Fixed Security vulnerability
- UPnP Buffer Overflow
- HTTP Buffer Overflow
For details visit: http://securityadvisories.dlink.com
---------------------------
Firmware: DIR890A1_FW108b03.bin
Date: 2015/07/07
Changes:
1. Apply Broadcom’s group key sync patch between driver and hardware. [DUSA Webber’s problem]
---------------------------
Firmware: DIR890A1_FW108b02.bin
Date: 2015/07/03
Changes:
1. Using different transaction IDs when doing DNS query.
2. Avoid query same DNS server twice at the same time.
---------------------------
Firmware: DIR890A1_FW108b01.bin
Date: 2015/06/30
Changes:
1. [Bug Fix] UI shows IPv6 WAN type as Auto detection after setting Link-local when WAN ethernet is not connected.
2. Increase the length of PPTP/L2TP server address characters to 32.
3. DHCP change to Unicast by default(Disable Always Broadcast in DHCP server settings) in Network.html.
4. [IP reservation] In some situation, the reserved IP will be given to another client. (Sync from main trunk)
5. Change IPv6 default mode back to auto detection.
---------------------------
Firmware: DIR890A1_FW107b12.bin
Date: 2015/06/26
Changes:
1. Fix that 802.11n (5GHz) devices are still able to connect DIR-890L.The r49935 have solved about 2.4g kind of 802.11n problem before, but the 5g band use the same rule cause to the ac only can still connect with 802.11n.
2. BTD2015041149 [Wizard] After default wizard finished, sometimes the 5G wireless settings are not changed.
a. remove 'Reboot' function.
b. restart WIFI service after SMARTCONNECT service restarted.
c. add timer for SMARTCONNECT service.
3. Restart IPv6 protocol stack in IPV6ENABLE event.To send IPv6 DAD in booting, we do not enable IPv6 protocol stack when starting PHYINF.ETH-X services.
4. For Russia, set IPv6 default mode to Link Local
---------------------------
Firmware: DIR890A1_FW107b11.bin
Date: 2015/06/09
Changes:
1. Reduce expiration time of SCB pending, improve 43602 memory usage.
---------------------------
Firmware: DIR890A1_FW107b10.bin(beta)
Date: 2015/06/05
Changes:
1. Fix some security issue from D-Link DIR-868L security report
2. Fix bug of kernel panic when enable Qos and connect to guest zone
3. fix bug of Parental Control in Home page will disappear
4. Fix SharePort plus not work issue.
5. Resolve few types of video file can’t be identified by DLNA.
6. Allow L2TP and PPTP can input domain name into Server IP Address field.
---------------------------
Firmware: DIR890A1_FW107b09.bin
Date: 2015/05/26
Changes:
1. Fix issue that wireless client identify icon doesn’t correct.
---------------------------
Firmware: DIR890A1_FW107b08.bin
Date: 2015/05/25
Changes:
1. Fix issue that wireless client identify icon doesn’t correct.
---------------------------
Firmware: DIR890A1_FW107b07.bin
Date: 2015/05/22
Changes:
1. Fix command injection by upnp m-search method.
2. Update QOS alert message for DUSA.
3. Update Russian translation.
4. Cannot use ipv6 address to login device web page with https when device using ipv6 static setting.
5. Reserve IP not work. [DEUR20150504000010-North Europe]
6. Fix SharePort plus not work issue.
7. Fix “IP address cannot be the same” message at wrong position.
8. Fix issue the clients disappear and re-appear in 3-5 sesonds on UI.
9. Resolve few types of video file can’t be identified by DLNA.
---------------------------
Firmware: DIR890A1_FW107b06.bin
Date: 2015/05/18
Changes:
1. Apply 2 Broadcom’s patches to fix 43602 firmware crash issues. [drop-expired-ampdu-rx-pkts.diff], [ignore_amsdu_ptks_with_invalid_scb.diff].
2. Fix wireless client band info at wrong position.
3. [DEUR20150429000011-Central Europe] UI only shows one USB drive when user plugs 2 USB drives.
---------------------------
Firmware: DIR890A1_FW107b05.bin
Date: 2015/05/14
Changes:
1. Fixed: IPv6 firewall still not works when setting IPv6 Firewall Rules to "Turn IPv6 Filtering ON and ALLOW rules listed".
2. Fixed STA band message overlay.
---------------------------
Firmware: DIR890A1_FW107b04.bin (beta firmware)
Date: 2015/05/13
Changes:
1. Add band information of wireless station in web UI Homepage.
---------------------------
Firmware: DIR890A1_FW107b03.bin
Date: 2015/05/12
Changes:
1. Fix IPv6 ingress filtering didn't work. When we modify setting and reboot, the setting lost.
---------------------------
Firmware: DIR890A1_FW107b02.bin
Date: 2015/05/07
Changes:
1. Modify some wifi parameters for 2.4g interference mitigation.
2. Fix driver (43602) crash issues [memory leak and driver trap].
3. Fix schedule not work properly [BTD2015030934].
4. Use buffer length checking memory manipulation in HNAP CGI.
5. Fix IP CAM (DCS-5029) cannot connect with WPA/PSK.
6. Add QOS bandwidth setting help message.
7. Modify QOS bandwidth from Kbps to Mbps.
8. Fix QOS has too low throughput than bandwidth setting.
9. Fix IPv6 firewall issue [DUSA20150506000001].
10. Rollback mydlink agent to 2.0.18-b25, avoid DLNA cannot list video files.
---------------------------
Firmware: DIR890A1_FW107b01.bin
Date: 2015/04/24
Changes:
1. Change smart connect setting will reboot DUT
2. Fix Host zone Smart connect setting would be modified via Guest zone
3. Avoid system hang (served, xmldb)
---------------------------
Firmware: DIR890A1_FW106b06.bin(beta)
Date: 2015/04/29
Changes:
1. fix the DNS server in LAN can't access internet issue
---------------------------
Firmware: DIR890A1_FW106b04.bin
Date: 2015/04/17
Changes:
2. The connected client number should not count the offline client but only connecting client.
3. 12 noon should not show 00:00 PM but 12:00 PM for D-Link OBU requestment.
4. Solve the cache issue with different firmware version.
a. add missing timestamp for some pages.
b. replace 'ini_ver' with timestamp.
4. Take care SetOperationMode implemented into SetMultipleActions.php to make sure QRS Mobile could work well.
Now DIR-890L only support wireless Router mode and wireless AP mode.
5. Prevent HNAP GetDeviceSettings command injection
a. Replace strstr function with strcmp function to check HNAP GetDeviceSettings to prevent command injection
b. Replace sprintf function with snprintf function to prevent the buffer overflow security issue.
---------------------------
Firmware: DIR890A1_FW106b03.bin
Date: 2015/04/10
Changes:
1. [BTD2015031091] [mydlink lite] Skip setup wizard and register mydlink, before DUT reboot the mydlink lite can't access DUT.
2. Fix WOL(wake on lan) not work
3. Set 802.1x to highest priority
4. Solve the issue the captcha login could not work well.
5. a.Extend reciprocal number to prevent sometimes the remote management will fail after saving settings serval times.
b.remote access should be changed to http while https server is disabled.
6. BCM patch to fix the memory leak problem
7. Update 43602 firmware for "BCM patch to fix the memory leak problem".
8. Solve the port forwarding issue
a. DIR_890_port forwarding rule issue[DUSA20150311000004-Canada]
b. DIR-890L Doesn't allow port forwarding with a single TCP or UDP port, but it does allow forwarding both![DUSA20150409000001-USA]
9. Work around the issue from D-Link OBU: Change MTU to 1300 and change back to 1492, MTU still 1300 actually after save settings. Reboot will resolve this issue.
10. NVR (beta) agent added in firmware, and no LAB test
---------------------------
Firmware: DIR890A1_FW106b02.bin
Date: 2015/03/25
Changes:
1. Modify client information in Home.html
a. Show the "OFFLINE" style for DHCP reservation client in Home.html if it is not connected to router now.
b. Add the "Add client DHCP reservation card add" to follow the D-Link New GUI design.
c. Add the error check if the DHCP reservation IP is conflict to another current client IP address.
2. Update wireless network interface card firmware. ([devel] We remove some mfg features from 43602 firmware. It should not be in normal firmware.)
---------------------------
Firmware: DIR890A1_FW106b01.bin
Date: 2015/03/20
Changes:
1. Checkout code from SVN server
2. fix when wan type is static, WAN LED turn to amber after unplug and plug in WAN Ethernet cable
3. fix the dhcpd daemon could not be executed if the hostname of DHCP reservation is empty
4. Add the error check if the reserve IP is not belonging to LAN IP
5. Apply BCM patch to fix the low signal power issue
---------------------------
Firmware: DIR890A1_FW105b04.bin
Date: 2015/03/17
Changes:
Base on DIR890A1_FW105b03.bin
1. BTD2015030846 [security] To set Primary SSID security as WEP and Guest security as WPA-PSK, then STA can not connect to Guest SSID.
SVN update aries/dlink.2013gui/services/SMARTCONNECT.php r52377
2. BTD2015030514 [AP mode] Can't access http://192.168.0.50 after saving any shreaport function
SVN update aries/progs/htdocs/hnap_ui/SetStorageUsers.php r52815
3. BTD2015030828 [AP+MAC Clone] MAC clone can't work on AP mode(DHCP/Static IP)
SVN update aries/dlink.2013gui/dir890/htdocs/web/Internet.html r52817
4. BTD2015030839 [Web UI][Guest zone] Can't disable 'Internet Access Only' function.
SVN update aries/dlink.2013gui/dir890/htdocs/web/GuestZone.html r52824
---------------------------
Firmware: DIR890A1_FW105b03.bin
Date: 2015/03/16
Changes:
Base on DIR890A1_FW105b02.bin
1. SVN update
aries/dlink.2013gui/dir890/htdocs/web/js/ initialJQ.js r52279
2. Solve the bugs in bug tracker
BTD2015030732 [Wizard] Default wizard can't work or cancel
---------------------------
Firmware: DIR890A1_FW105b02.bin
Date: 2015/03/13
Changes:
Base on DIR890A1_FW105b01.bin
1. SVN update
aries/dlink.2013gui/dir890/htdocs/web/GuestZone.html r52764
aries/dlink.2013gui/dir890/htdocs/web/Home.html r52189
aries/dlink.2013gui/dir890/htdocs/web/Wizard.html r52370
aries/dlink.2013gui/dir890/services/LAYOUT.php r52780
aries/progs/htdocs/hnap_ui/SetUSBStorageSettings.php r52246
aries/progs/htdocs/hnap_ui/SetWanSettings.php r52780
aries/progs/htdocs/hnap_ui/SetSmartconnectSettings.php r52779
2. Solve the bugs in bug tracker
BTD2015030293 [WebUI+Guest+Schedule] Enable primary and guest wifi by schedule, guest wifi can work well but it shows disabled on guest zone page
BTD2015030303 [Web UI] Enable guest zone with none security, after save the setting the password fiels will be grayed.
BTD2015030449 [WebUI+Guest] Guest SSID textbox need fool proof(null SSID can be saved but guest wifi won't work)
BTD2015030467 [AP mode+IP setting] Change DUT's IP mode(Static/DHCP) but it need reboot to tack effect.
BTD2015030512 [AP Mode+DHCP] Enable DLNA on AP mode, then DUT's DHCP server will be enabled
BTD2015030514 [AP mode] Can't access http://192.168.0.50 after saving any shreaport function
BTD2015030517 [CN+Wizard] Check internet connectivity will fail when WAN detect DHCP mode
BTD2015030621 [AP+Wireless] Enable guest zone then change to AP mode, primary and guest wifi will become none security
BTD2015030626 [Guest+security] Can't change security from WPA to None security
Nota edizione US
DIR-890L Firmware Release Notes
Firmware: FW v120b01
Hardware: Rev. A1
Release Date: 2017/10/2
Note:
1. The firmware version is advanced to v120b01
2. The firmware v120b01 must be upgraded from the transitional version of firmware v111b04.
Problems Resolved:
• Fixed the following security issues
• Add Firmware Protection to BIN file and System
• WAN && LAN - XSS exploit
▪ (CVE-2017-14413, CVE-2017-14414, CVE-2017-14415, CVE-2017-14416)
• WAN - Weak Cloud protocol
▪ (CVE-2017-14419, CVE-2017-14420)
• WAN && LAN - Stunnel private keys
▪ (CVE-2017-14422)
• WAN && LAN - Nonce brute forcing for DNS configuration
▪ (CVE-2017-14423)
• Local - Weak files permission and credentials stored in clear text
▪ (CVE-2017-14424, CVE-2017-14425, CVE-2017-14426, CVE-2017-14427, CVE-2017-14428)
• LAN – DoS attack against some daemons
▪ (CVE-2017-14430)
• Security fixes to PHP CGI files to mitigate exposing credentials
• Correct stack overflow vulnerability caused by HNAP