D-Link G604T network adaptor

The DSL-G604T is a first D-Link Wireless/ADSL router which firmware is based on open source the MontaVista Linux.[1] The DSL-G604T was introduced in November 2004.[2] This model has been discontinued.

Specifications

edit

Hardware

edit
  • CPU: Texas Instrument AR7W MIPS 4KEc based SoC with built-in ADSL and Ethernet interfaces
  • DRAM Memory: 16Mb
  • Flash Memory: 2Mb SquashFS file system
  • Wi-Fi: TI MiniPCI card
  • Ethernet: 5-port Ethernet hub (1 internal, 4 external)

Firmware

edit

The G604T runs MontaVista and busybox Linux which allows a degrejje of customisation with customised firmware. These and similar units from D-Link appear to have an issue that causes certain services to fail when using the factory provided firmware, namely the Debian package update service being interrupted due to a faulty DNS through DHCP issue at the kernel level. A v2.00B06.AU_20060728 patch was made available through their downloads section that provided some level of correction, but it was not a complete fix and the issue would resurface intermittently. When the issue was originally reported, D-Link seemed to have misunderstood that the same issue has been discovered by the Linux community at large to be common across a number of their router models and they failed to provide a complete fix across the board for all adsl router models.

Russian version of the firmware (prefix .RU, e.g. V1.00B02T02.RU.20041014) has restrictions on configuring firewall rules – user can only change sender's address (computer address in the LAN segment) and the recipient's port. The web interface with Russian firmware also differs from the English interface.[3]

Default settings

edit

When running the D-link DSL-G604T router for the first time (or resetting), the device is configured with a default IP address (192.168.1.1), username (admin) and password (admin). Default username and password can also be printed on the router itself, in the manual, or on the box.[4]

Problems

edit

Security

edit

D-Link DSL-G604T has Cross-site scripting (XSS) vulnerability in cgi-bin/webcm on the router allows remote attackers to inject arbitrary web script or HTML via the var:category parameter, as demonstrated by a request for advanced/portforw.htm on the fan page.

Directory traversal vulnerability in webcam in the D-Link DSL-G604T Wireless ADSL Router Modem allows remote attackers to read arbitrary files via an absolute path in the getpage parameter.[5]

When /cgi-bin/firmwarecfg is executed, allows remote attackers to bypass authentication if their IP address already exists in /var/tmp/fw_ip or if their request is the first, which causes /var/tmp/fw_ip to be created and contain their IP address.[6]

Noise

edit

Owners reported that the router emitted a low, high-pitched sound when the ADSL line was synchronized.[7][8]

Reception

edit

The DSL-G604T received positive reviews, receiving an 7.9/10 from PCActual,[9] 3/5 from PCWorld.[10] According to CNET, "DSL-G604T is a ADSL2/2 modem router with some serious stability issues".[11]

Similar models

edit

The DSL-G624T, DSL-G664T and DSL-G684T routers are very similar to the G604T.

References

edit
  1. ^ "D-link access point now running on Linux". Irish Silicon. Archived from the original on 2009-01-02. Retrieved 29 December 2020.
  2. ^ "Device Profile: D-Link DSL-G604T wired/wireless ADSL router". Linux Devices Archive. Archived from the original on 2018-10-31. Retrieved 29 December 2020.
  3. ^ "Wireless ADSL router D-Link DSL-G604T". iXBT (in Russian). Archived from the original on 2005-12-23. Retrieved 29 December 2020.
  4. ^ "D-Link DSL-G604T". Router Passwords. Archived from the original on 2020-09-22. Retrieved 29 December 2020.
  5. ^ "CVE-2006-2337". infosec.cert-pa.it. Archived from the original on 2021-08-25. Retrieved 29 December 2020.
  6. ^ "Dsl-g604t: Security Vulnerabilities". CVE Details. Archived from the original on 2011-12-14. Retrieved 29 December 2020.
  7. ^ "D-Link DSL-G604T Hacking". Justin's Stuff. Archived from the original on 2020-10-31. Retrieved 29 December 2020.
  8. ^ "Dlink DSL-G604T DNS Resolution Problems". Jethro Carr. 10 January 2007. Archived from the original on 2013-02-12. Retrieved 29 December 2020.
  9. ^ "D-Link DSL-G604T" (PDF). PC Actual. p. 116. Retrieved 29 December 2020.[permanent dead link]
  10. ^ "Review D-Link DSL-G604T". PC World. Archived from the original on 2021-01-28. Retrieved 29 December 2020.
  11. ^ "D-Link DSL-G604T review". C NET. Archived from the original on 2021-02-11. Retrieved 29 December 2020.
edit