(01) - CybersecurityDMSA-2025-ES-001

Subdomain Vulnerability in Spanish DGT Domain

A misconfiguration in subdomain management for dgt.es was discovered, potentially allowing attackers to host malicious content under official-looking subdomains.

29 September 20252 min readCybersecurityReports

Executive Summary

Dymo's automated security scanning detected a subdomain misconfiguration vulnerability in the Spanish Directorate General of Traffic (DGT) domain (dgt.es). This flaw could enable attackers to create malicious subdomains that appear to originate from the official government domain.

Affected Entity

  • Organization: Dirección General de Tráfico (DGT)
  • Country: Spain
  • Domain: dgt.es
  • Function: Traffic regulation and road safety

Vulnerability Details

Type

DNS Subdomain Misconfiguration / Wildcard Abuse

Severity

Medium-High (CVSS 6.1)

Technical Analysis

The vulnerability exists due to:

  1. Improper DNS Configuration: Wildcard records allowing arbitrary subdomain creation
  2. Missing Validation: No verification of legitimate subdomain ownership
  3. SSL Gaps: Certificates not enforced on all subdomains
  4. Lack of Monitoring: No detection of unauthorized subdomain creation

Attack Scenarios

Exploitation could result in:

  • Phishing Sites: Fake DGT portals for credential theft
  • Malware Distribution: Host malicious downloads on trusted domain
  • Email Spoofing: Bypass SPF/DKIM using subdomain
  • Service Impersonation: Fake payment or appointment scheduling sites

Impact

Given DGT's role in vehicle registration, driver licensing, and traffic fines:

  • High-value targets: Vehicle owners, driving schools, transport companies
  • Trust exploitation: Users expect official government URLs
  • Financial fraud: Fake fine payment portals
  • Data harvesting: Personal and vehicle information collection

Responsible Disclosure

Reported to:

  • DGT IT Security Team
  • INCIBE (Instituto Nacional de Ciberseguridad)
  • Spanish Ministry of Interior
  1. Restrict wildcard DNS entries
  2. Implement CAA records for SSL certificates
  3. Deploy subdomain monitoring solutions
  4. Enable certificate transparency logging
  5. Regular DNS configuration audits

This vulnerability was identified through Dymo's continuous government sector scanning.