4,00,000 Devices of D-Link are Vulnerable including Webcams, Modems and Storage Devices!

About a month ago, a major security flaw was discovered by Security Researchers of Senrio in Wi-Fi cameras of D-Link. The DCS-930L model of D-Link’s wi-fi cameras was vulnerable and it was allowing attackers to take root privileges by sending a specially crafted command. The products of D-Link are one from the highest selling products of Amazon. From here you can guess, how many users D-link have the worldwide.
D-Link was agree with the researchers regarding this security flaw. After finding this vulnerability, researchers continued their investigation to find vulnerabilities in the other products of D-Link. During this investigation they came to know that more than 100 D-Link products, contains same security issues. According to researchers, 120 products of D-Link are vulnerable. Modems, Cameras, Routers, Storage Devices and many other products are included in it.
What is the vulnerability?
The vulnerability exists in a firmware service of D-Link. The name of this service is “DCP”. The work of this service is to listing the remote commands on Port Number 5978 and then process it for further executions. D-Link has a service “mydlink” which is beneficial for users to make connection with their even when they are outside of the network. This “DCP” service is a part of “mydlink” module. Users can control their network by using an application which is available on the stores of all smartphones.
Which devices are Vulnerable?
According to the security researchers of Senrio, there are 4,00,000 D-Link devices which are vulnerable. The actual number of vulnerable devices is still unknown because D-Link have not published any report about it. Webcams are on the top of researchers list because it has the highest number of users. 70% of users are still using the flawed version of these cameras. Routers, Modems, Cloud Cameras and Storage Devices comes after it.
What can Hackers do?
Hackers could include vulnerable devices into botnets and do they can use it for illegal activities. LizadStresser named botnet is already attacking IOT (internet of things) devices in wild. This botnet has been prepared by hacking group LizardSquare. They are also using some botnets to hack wi-fi cameras and further they are using hacked IP’s to perform D-Dos attacks on big websites.