D-Link Multiple Devices Backdoor

Summary
Various D-Link DSL routers are susceptible to a remote authentication bypass vulnerability.
Impact
This vulnerability allows remote attackers to gain complete administrative access to affected devices.
Solution
Ask the Vendor for an update.
Insight
By setting the User-Agent header to 'xmlset_roodkcableoj28840ybtide', it is possible to access the web interface without any authentication.
Affected
Various D-Link routers are affected.
Detection
Try to bypass authentication by using 'xmlset_roodkcableoj28840ybtide' as HTTP User-Agent.
References