ID

VAR-201312-0290


CVE

CVE-2013-7005


TITLE

plural D-Link Vulnerability in obtaining important information in the firmware of router products

Trust: 0.8

sources: JVNDB: JVNDB-2013-005616

DESCRIPTION

D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 stores account passwords in cleartext, which allows local users to obtain sensitive information by reading the Users[#]["Password"] fields in /tmp/teamf1.cfg.ascii. D-Link DSR is a wireless service router product. There are multiple information disclosure vulnerabilities in the D-Link DSR Router Series account credentials. Allows an attacker to access sensitive information. The information obtained may lead to further attacks. The following products and versions are affected: DSR-150 with firmware version 1.08B29 and earlier; DSR-150N with firmware version 1.05B51 and earlier; DSR-250 and DSR-250N with firmware version 1.08B39 and earlier; DSR-500, DSR-500N, DSR-1000, DSR-1000N with previous firmware versions

Trust: 2.52

sources: NVD: CVE-2013-7005 // JVNDB: JVNDB-2013-005616 // CNVD: CNVD-2013-15507 // BID: 64461 // VULHUB: VHN-67007

IOT TAXONOMY

category:['IoT', 'Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2013-15507

AFFECTED PRODUCTS

vendor:dlinkmodel:dsr-150scope:lteversion:1.08b29

Trust: 1.0

vendor:dlinkmodel:dsr-500nscope:eqversion:1.03b36

Trust: 1.0

vendor:dlinkmodel:dsr-1000nscope:eqversion:1.02b25

Trust: 1.0

vendor:dlinkmodel:dsr-500nscope:eqversion:1.06b43

Trust: 1.0

vendor:dlinkmodel:dsr-500nscope:eqversion:1.03b43

Trust: 1.0

vendor:dlinkmodel:dsr-250nscope:eqversion:1.08b31

Trust: 1.0

vendor:dlinkmodel:dsr-150nscope:lteversion:1.05b48

Trust: 1.0

vendor:dlinkmodel:dsr-1000nscope:eqversion:1.03b12

Trust: 1.0

vendor:dlinkmodel:dsr-1000nscope:eqversion: -

Trust: 1.0

vendor:dlinkmodel:dsr-500scope:eqversion:1.03b23

Trust: 1.0

vendor:dlinkmodel:dsr-250scope:eqversion:1.05b53

Trust: 1.0

vendor:dlinkmodel:dsr-1000scope:eqversion:1.03b23

Trust: 1.0

vendor:dlinkmodel:dsr-500scope:eqversion: -

Trust: 1.0

vendor:dlinkmodel:dsr-1000scope:eqversion:1.04b58

Trust: 1.0

vendor:dlinkmodel:dsr-500scope:eqversion:1.04b58

Trust: 1.0

vendor:dlinkmodel:dsr-1000scope:eqversion:1.03b27

Trust: 1.0

vendor:dlinkmodel:dsr-500scope:eqversion:1.03b27

Trust: 1.0

vendor:dlinkmodel:dsr-500nscope:eqversion:1.02b11

Trust: 1.0

vendor:dlinkmodel:dsr-150scope:eqversion:1.05b50

Trust: 1.0

vendor:dlinkmodel:dsr-150nscope:eqversion: -

Trust: 1.0

vendor:dlinkmodel:dsr-500nscope:eqversion:1.06b53

Trust: 1.0

vendor:dlinkmodel:dsr-1000scope:eqversion:1.03b36

Trust: 1.0

vendor:dlinkmodel:dsr-500scope:eqversion:1.03b36

Trust: 1.0

vendor:dlinkmodel:dsr-250nscope:lteversion:1.08b39

Trust: 1.0

vendor:dlinkmodel:dsr-250scope:eqversion:1.08b31

Trust: 1.0

vendor:dlinkmodel:dsr-500nscope:eqversion: -

Trust: 1.0

vendor:dlinkmodel:dsr-1000nscope:lteversion:1.08b51

Trust: 1.0

vendor:dlinkmodel:dsr-1000scope:eqversion:1.03b43

Trust: 1.0

vendor:dlinkmodel:dsr-500scope:eqversion:1.03b43

Trust: 1.0

vendor:dlinkmodel:dsr-1000scope:eqversion: -

Trust: 1.0

vendor:dlinkmodel:dsr-250nscope:eqversion:1.01b46

Trust: 1.0

vendor:dlinkmodel:dsr-500nscope:eqversion:1.02b25

Trust: 1.0

vendor:dlinkmodel:dsr-1000scope:eqversion:1.01b50

Trust: 1.0

vendor:dlinkmodel:dsr-500scope:eqversion:1.06b43

Trust: 1.0

vendor:dlinkmodel:dsr-150scope:eqversion: -

Trust: 1.0

vendor:dlinkmodel:dsr-1000scope:eqversion:1.06b43

Trust: 1.0

vendor:dlinkmodel:dsr-500nscope:eqversion:1.03b12

Trust: 1.0

vendor:dlinkmodel:dsr-500nscope:lteversion:1.08b51

Trust: 1.0

vendor:dlinkmodel:dsr-1000scope:eqversion:1.02b11

Trust: 1.0

vendor:dlinkmodel:dsr-500scope:eqversion:1.02b11

Trust: 1.0

vendor:dlinkmodel:dsr-250nscope:eqversion:1.01b56

Trust: 1.0

vendor:dlinkmodel:dsr-1000nscope:eqversion:1.03b23

Trust: 1.0

vendor:dlinkmodel:dsr-1000nscope:eqversion:1.04b58

Trust: 1.0

vendor:dlinkmodel:dsr-1000scope:eqversion:1.06b53

Trust: 1.0

vendor:dlinkmodel:dsr-500scope:eqversion:1.06b53

Trust: 1.0

vendor:dlinkmodel:dsr-250scope:eqversion:1.01b46

Trust: 1.0

vendor:dlinkmodel:dsr-1000nscope:eqversion:1.03b27

Trust: 1.0

vendor:dlinkmodel:dsr-250nscope:eqversion:1.05b20

Trust: 1.0

vendor:dlinkmodel:dsr-1000scope:eqversion:1.02b25

Trust: 1.0

vendor:dlinkmodel:dsr-500scope:eqversion:1.02b25

Trust: 1.0

vendor:dlinkmodel:dsr-1000scope:eqversion:1.03b12

Trust: 1.0

vendor:dlinkmodel:dsr-150scope:eqversion:1.05b46

Trust: 1.0

vendor:dlinkmodel:dsr-500scope:eqversion:1.03b12

Trust: 1.0

vendor:dlinkmodel:dsr-1000nscope:eqversion:1.03b36

Trust: 1.0

vendor:dlinkmodel:dsr-150scope:eqversion:1.05b35

Trust: 1.0

vendor:dlinkmodel:dsr-250scope:lteversion:1.08b39

Trust: 1.0

vendor:dlinkmodel:dsr-1000nscope:eqversion:1.03b43

Trust: 1.0

vendor:dlinkmodel:dsr-1000nscope:eqversion:1.06b43

Trust: 1.0

vendor:dlinkmodel:dsr-1000scope:lteversion:1.08b51

Trust: 1.0

vendor:dlinkmodel:dsr-250scope:eqversion:1.01b56

Trust: 1.0

vendor:dlinkmodel:dsr-500nscope:eqversion:1.03b23

Trust: 1.0

vendor:dlinkmodel:dsr-1000nscope:eqversion:1.01b50

Trust: 1.0

vendor:dlinkmodel:dsr-250nscope:eqversion:1.05b53

Trust: 1.0

vendor:dlinkmodel:dsr-250scope:eqversion: -

Trust: 1.0

vendor:dlinkmodel:dsr-150scope:eqversion:1.05b29

Trust: 1.0

vendor:dlinkmodel:dsr-250scope:eqversion:1.05b20

Trust: 1.0

vendor:dlinkmodel:dsr-1000nscope:eqversion:1.02b11

Trust: 1.0

vendor:dlinkmodel:dsr-500nscope:eqversion:1.04b58

Trust: 1.0

vendor:dlinkmodel:dsr-500nscope:eqversion:1.03b27

Trust: 1.0

vendor:dlinkmodel:dsr-500scope:lteversion:1.08b51

Trust: 1.0

vendor:dlinkmodel:dsr-1000nscope:eqversion:1.06b53

Trust: 1.0

vendor:d linkmodel:dsr-1000scope: - version: -

Trust: 0.8

vendor:d linkmodel:dsr-1000scope:ltversion:1.08b77

Trust: 0.8

vendor:d linkmodel:dsr-1000nscope: - version: -

Trust: 0.8

vendor:d linkmodel:dsr-1000nscope:ltversion:1.08b77

Trust: 0.8

vendor:d linkmodel:dsr-150scope: - version: -

Trust: 0.8

vendor:d linkmodel:dsr-150scope:ltversion:1.08b44

Trust: 0.8

vendor:d linkmodel:dsr-150nscope: - version: -

Trust: 0.8

vendor:d linkmodel:dsr-150nscope:ltversion:1.05b64

Trust: 0.8

vendor:d linkmodel:dsr-250scope: - version: -

Trust: 0.8

vendor:d linkmodel:dsr-250scope:ltversion:1.08b44

Trust: 0.8

vendor:d linkmodel:dsr-250nscope: - version: -

Trust: 0.8

vendor:d linkmodel:dsr-250nscope:ltversion:1.08b44

Trust: 0.8

vendor:d linkmodel:dsr-500scope: - version: -

Trust: 0.8

vendor:d linkmodel:dsr-500scope:ltversion:1.08b77

Trust: 0.8

vendor:d linkmodel:dsr-500nscope: - version: -

Trust: 0.8

vendor:d linkmodel:dsr-500nscope:ltversion:1.08b77

Trust: 0.8

vendor:d linkmodel:dsr-150 v1.08b44scope:ltversion: -

Trust: 0.6

vendor:d linkmodel:dsr-150n v1.05b64scope:ltversion: -

Trust: 0.6

vendor:d linkmodel:dsr-250 and dsr-250n v1.08b44scope:ltversion: -

Trust: 0.6

vendor:d linkmodel:dsr-500 and dsr-500n v1.08b77scope:ltversion: -

Trust: 0.6

vendor:d linkmodel:dsr-1000 and dsr-1000n v1.08b77scope:ltversion: -

Trust: 0.6

vendor:d linkmodel:dsr-250nscope:eqversion:1.08b31

Trust: 0.6

vendor:d linkmodel:dsr-1000scope:eqversion:1.03b36

Trust: 0.6

vendor:d linkmodel:dsr-500nscope:eqversion:1.02b11

Trust: 0.6

vendor:d linkmodel:dsr-500nscope:eqversion:1.03b12

Trust: 0.6

vendor:d linkmodel:dsr-500nscope:eqversion:1.02b25

Trust: 0.6

vendor:d linkmodel:dsr-500nscope:eqversion:1.03b36

Trust: 0.6

vendor:d linkmodel:dsr-500nscope:eqversion:1.03b27

Trust: 0.6

vendor:d linkmodel:dsr-250nscope:eqversion:1.05b53

Trust: 0.6

vendor:d linkmodel:dsr-1000scope:eqversion:1.03b12

Trust: 0.6

vendor:d linkmodel:dsr-500nscope:eqversion:1.03b23

Trust: 0.6

vendor:d linkmodel:dsr-500nscope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dsr-500scope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dsr-250nscope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dsr-250scope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dsr-150nscope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dsr-150scope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dsr-1000nscope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dsr-1000scope:eqversion:0

Trust: 0.3

vendor:d linkmodel:dsr-500n 1.08b77scope:neversion: -

Trust: 0.3

vendor:d linkmodel:dsr-500 1.08b77scope:neversion: -

Trust: 0.3

vendor:d linkmodel:dsr-250n 1.08b44scope:neversion: -

Trust: 0.3

vendor:d linkmodel:dsr-250 1.08b44scope:neversion: -

Trust: 0.3

vendor:d linkmodel:dsr-150n 1.05b64scope:neversion: -

Trust: 0.3

vendor:d linkmodel:dsr-150 1.08b44scope:neversion: -

Trust: 0.3

vendor:d linkmodel:dsr-1000n 1.08b77scope:neversion: -

Trust: 0.3

vendor:d linkmodel:dsr-1000 1.08b77scope:neversion: -

Trust: 0.3

sources: CNVD: CNVD-2013-15507 // BID: 64461 // JVNDB: JVNDB-2013-005616 // CNNVD: CNNVD-201312-401 // NVD: CVE-2013-7005

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-7005
value: MEDIUM

Trust: 1.0

NVD: CVE-2013-7005
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2013-15507
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201312-401
value: LOW

Trust: 0.6

VULHUB: VHN-67007
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2013-7005
severity: MEDIUM
baseScore: 4.9
vectorString: AV:L/AC:L/AU:N/C:C/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2013-15507
severity: MEDIUM
baseScore: 4.9
vectorString: AV:L/AC:L/AU:N/C:C/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-67007
severity: MEDIUM
baseScore: 4.9
vectorString: AV:L/AC:L/AU:N/C:C/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2013-15507 // VULHUB: VHN-67007 // JVNDB: JVNDB-2013-005616 // CNNVD: CNNVD-201312-401 // NVD: CVE-2013-7005

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.9

sources: VULHUB: VHN-67007 // JVNDB: JVNDB-2013-005616 // NVD: CVE-2013-7005

THREAT TYPE

local

Trust: 0.9

sources: BID: 64461 // CNNVD: CNNVD-201312-401

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201312-401

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-005616

PATCH

title:Services Routersurl:http://www.dlink.com/us/en/business-solutions/security/services-routers

Trust: 0.8

title:ルータ/ファイアウォールurl:http://www.dlink-jp.com/router-firewall

Trust: 0.8

title:Downloadsurl:http://tsd.dlink.com.tw/

Trust: 0.8

title:D-Link DSR Router Series account credentials have multiple patches for information disclosure vulnerabilitiesurl:https://www.cnvd.org.cn/patchInfo/show/41954

Trust: 0.6

title:DSR-250N_A1_FW1url:http://123.124.177.30/web/xxk/bdxqById.tag?id=47082

Trust: 0.6

title:DSR-250_A1_FW1url:http://123.124.177.30/web/xxk/bdxqById.tag?id=47081

Trust: 0.6

title:DSR-150N_A2_FW1url:http://123.124.177.30/web/xxk/bdxqById.tag?id=47080

Trust: 0.6

title:DSR-150_A2_FW1url:http://123.124.177.30/web/xxk/bdxqById.tag?id=47079

Trust: 0.6

title:DSR-150_A1_FW1url:http://123.124.177.30/web/xxk/bdxqById.tag?id=47078

Trust: 0.6

title:DSR-1000_A1_FW1url:http://123.124.177.30/web/xxk/bdxqById.tag?id=47085

Trust: 0.6

title:DSR-500N_A1_FW1url:http://123.124.177.30/web/xxk/bdxqById.tag?id=47084

Trust: 0.6

title:DSR-500_A1_FW1url:http://123.124.177.30/web/xxk/bdxqById.tag?id=47083

Trust: 0.6

title:DSR-1000N_A1_FW1url:http://123.124.177.30/web/xxk/bdxqById.tag?id=47086

Trust: 0.6

sources: CNVD: CNVD-2013-15507 // JVNDB: JVNDB-2013-005616 // CNNVD: CNNVD-201312-401

EXTERNAL IDS

db:NVDid:CVE-2013-7005

Trust: 3.4

db:EXPLOIT-DBid:30061

Trust: 1.7

db:BIDid:64461

Trust: 1.0

db:JVNDBid:JVNDB-2013-005616

Trust: 0.8

db:CNNVDid:CNNVD-201312-401

Trust: 0.7

db:CNVDid:CNVD-2013-15507

Trust: 0.6

db:VULHUBid:VHN-67007

Trust: 0.1

sources: CNVD: CNVD-2013-15507 // VULHUB: VHN-67007 // BID: 64461 // JVNDB: JVNDB-2013-005616 // CNNVD: CNNVD-201312-401 // NVD: CVE-2013-7005

REFERENCES

url:http://www.exploit-db.com/exploits/30061

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-7005

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-7005

Trust: 0.8

url:http://www.securityfocus.com/bid/64461

Trust: 0.6

url:http://www.dlink.com/us/en/business-solutions/security/services-routers/dsr-500n-wireless-n-unified-services-router

Trust: 0.3

url:http://www.dlink.com/

Trust: 0.3

sources: CNVD: CNVD-2013-15507 // VULHUB: VHN-67007 // BID: 64461 // JVNDB: JVNDB-2013-005616 // CNNVD: CNNVD-201312-401 // NVD: CVE-2013-7005

CREDITS

Unknown

Trust: 0.3

sources: BID: 64461

SOURCES

db:CNVDid:CNVD-2013-15507
db:VULHUBid:VHN-67007
db:BIDid:64461
db:JVNDBid:JVNDB-2013-005616
db:CNNVDid:CNNVD-201312-401
db:NVDid:CVE-2013-7005

LAST UPDATE DATE

2025-04-11T23:03:51.876000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-15507date:2013-12-24T00:00:00
db:VULHUBid:VHN-67007date:2013-12-19T00:00:00
db:BIDid:64461date:2013-12-19T00:00:00
db:JVNDBid:JVNDB-2013-005616date:2013-12-20T00:00:00
db:CNNVDid:CNNVD-201312-401date:2023-04-27T00:00:00
db:NVDid:CVE-2013-7005date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:CNVDid:CNVD-2013-15507date:2013-12-24T00:00:00
db:VULHUBid:VHN-67007date:2013-12-19T00:00:00
db:BIDid:64461date:2013-12-19T00:00:00
db:JVNDBid:JVNDB-2013-005616date:2013-12-20T00:00:00
db:CNNVDid:CNNVD-201312-401date:2013-12-25T00:00:00
db:NVDid:CVE-2013-7005date:2013-12-19T04:24:57.493