ID

VAR-201309-0581


TITLE

Multiple vulnerabilities in the D-Link DIR-505 router

Trust: 0.6

sources: CNVD: CNVD-2013-12987

DESCRIPTION

The D-Link Dir-505 is a wireless router device. There are several security vulnerabilities in D-Link Dir-505: 1. The configuration file encryption provided by the device has a security vulnerability, allowing an attacker to exploit the vulnerability to decrypt the contents of the configuration file and obtain sensitive information. 2. The \"Ping Test\" function in the \"/System_Check.htm\" page of the device incorrectly filters the \"ip_addr\" parameter data, allowing an attacker to exploit the vulnerability to submit malicious data to execute arbitrary OS commands. 3. A device traversal vulnerability exists in the device, allowing remote attackers to exploit the vulnerability to obtain system file content or upload arbitrary files and execute them. 4. There is a built-in account that allows an attacker to exploit the account for unauthorized operations. 5, \"my_cgi.cgi\" has a security vulnerability that allows a remote attacker to exploit the vulnerability to perform a login operation to upload a malicious configuration file. The following security vulnerabilities exist in D-Link DIR-505 router 1.06 and earlier versions: 1. Command injection vulnerability 2. Directory traversal vulnerability 4. Multiple authentication bypass vulnerability. There may also be other forms of attacks. D-Link DIR-505 running firmware versions 1.06 and prior are vulnerable

Trust: 1.35

sources: CNVD: CNVD-2013-12987 // CNNVD: CNNVD-201309-090 // BID: 62283

IOT TAXONOMY

category:['IoT', 'Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2013-12987

AFFECTED PRODUCTS

vendor:d linkmodel:dir-505scope: - version: -

Trust: 0.6

vendor:d linkmodel:dir-505scope:eqversion:1.06

Trust: 0.3

vendor:d linkmodel:dir-505scope:neversion:1.07

Trust: 0.3

sources: CNVD: CNVD-2013-12987 // BID: 62283

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2013-12987
value: HIGH

Trust: 0.6

CNVD: CNVD-2013-12987
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2013-12987

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201309-090

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-201309-090

PATCH

title:D-Link DIR-505 router has multiple vulnerabilitiesurl:https://www.cnvd.org.cn/patchinfo/show/39490

Trust: 0.6

sources: CNVD: CNVD-2013-12987

EXTERNAL IDS

db:BIDid:62283

Trust: 1.5

db:CNVDid:CNVD-2013-12987

Trust: 0.6

db:CNNVDid:CNNVD-201309-090

Trust: 0.6

sources: CNVD: CNVD-2013-12987 // BID: 62283 // CNNVD: CNNVD-201309-090

REFERENCES

url:http://www.securityfocus.com/archive/1/528516

Trust: 0.6

url:http://www.securityfocus.com/bid/62283

Trust: 0.6

url:http://www.dlink.co.in/products/?pid=584

Trust: 0.3

url:http://www.dlink.com/

Trust: 0.3

url:http://seclists.org/bugtraq/2013/sep/30

Trust: 0.3

sources: CNVD: CNVD-2013-12987 // BID: 62283 // CNNVD: CNNVD-201309-090

CREDITS

Alessandro Di Pinto

Trust: 0.9

sources: BID: 62283 // CNNVD: CNNVD-201309-090

SOURCES

db:CNVDid:CNVD-2013-12987
db:BIDid:62283
db:CNNVDid:CNNVD-201309-090

LAST UPDATE DATE

2022-05-17T02:00:03.474000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-12987date:2013-09-13T00:00:00
db:BIDid:62283date:2013-09-09T00:00:00
db:CNNVDid:CNNVD-201309-090date:2013-09-11T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2013-12987date:2013-09-12T00:00:00
db:BIDid:62283date:2013-09-09T00:00:00
db:CNNVDid:CNNVD-201309-090date:2013-09-11T00:00:00