ID

VAR-201405-0652


TITLE

Multiple vulnerabilities in D-Link DIR-855L and DIR-835

Trust: 0.6

sources: CNVD: CNVD-2014-03069

DESCRIPTION

The D-Link DIR-855L and DIR-835 are router devices. There are several security vulnerabilities in D-Link DIR-855L and DIR-835: 1. The device fails to properly restrict access to the tools_admin.asp script, allowing attackers to exploit the vulnerability access restricted feature. 2. There is an error in processing requests through TCP 8080 and CGI/SSI/ accessing hnap.cgi to obtain sensitive information. 3. Inputs submitted via the \"action\" GET parameter are missing filtering before returning to the user, allowing remote attackers to exploit the vulnerability to inject malicious scripts or HTML code to obtain sensitive information or hijack user sessions when malicious data is viewed.

Trust: 0.6

sources: CNVD: CNVD-2014-03069

IOT TAXONOMY

category:['IoT', 'Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-03069

AFFECTED PRODUCTS

vendor:d linkmodel:dir-855lscope: - version: -

Trust: 0.6

vendor:d linkmodel:dir-835scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2014-03069

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2014-03069
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2014-03069
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2014-03069

PATCH

title:D-Link DIR-855L and DIR-835 have multiple vulnerabilitiesurl:https://www.cnvd.org.cn/patchinfo/show/45674

Trust: 0.6

sources: CNVD: CNVD-2014-03069

EXTERNAL IDS

db:SECUNIAid:58194

Trust: 0.6

db:CNVDid:CNVD-2014-03069

Trust: 0.6

sources: CNVD: CNVD-2014-03069

REFERENCES

url:http://secunia.com/advisories/58194/

Trust: 0.6

sources: CNVD: CNVD-2014-03069

SOURCES

db:CNVDid:CNVD-2014-03069

LAST UPDATE DATE

2022-05-17T02:02:30.025000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-03069date:2014-05-20T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2014-03069date:2014-05-19T00:00:00