ID

VAR-201501-0772


TITLE

D-Link DSL-2740R Web Interface Authentication Bypass Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2015-00835

DESCRIPTION

D-Link DSL-2740R is an ADSL wireless router product from D-Link. There are security holes in D-Link DSL-2740R. Attackers can use this vulnerability to modify DNS settings, and perform man-in-the-middle attacks, session hijacking attacks, or denial-of-service attacks between clients and DNS servers

Trust: 1.35

sources: CNVD: CNVD-2015-00835 // CNNVD: CNNVD-201501-708 // BID: 72339

IOT TAXONOMY

category:['IoT', 'Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2015-00835

AFFECTED PRODUCTS

vendor:d linkmodel:dsl-2740rscope: - version: -

Trust: 0.6

vendor:dlinkmodel:dsl-2740rscope:eqversion:0

Trust: 0.3

sources: CNVD: CNVD-2015-00835 // BID: 72339

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2015-00835
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2015-00835
severity: MEDIUM
baseScore: 5.8
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2015-00835

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201501-708

TYPE

Design Error

Trust: 0.3

sources: BID: 72339

EXTERNAL IDS

db:BIDid:72339

Trust: 1.5

db:EXPLOITDBid:35917

Trust: 0.6

db:EXPLOIT-DBid:35917

Trust: 0.6

db:CNVDid:CNVD-2015-00835

Trust: 0.6

db:CNNVDid:CNNVD-201501-708

Trust: 0.6

sources: CNVD: CNVD-2015-00835 // BID: 72339 // CNNVD: CNNVD-201501-708

REFERENCES

url:http://www.securityfocus.com/bid/72339

Trust: 1.2

url:http://www.exploit-db.com/exploits/35917/

Trust: 0.6

url:http://www.dlink.com/uk/en/support/product/dsl-2740r-wireless-n-adsl2-4-port-modem-router

Trust: 0.3

sources: CNVD: CNVD-2015-00835 // BID: 72339 // CNNVD: CNNVD-201501-708

CREDITS

Todor Donev

Trust: 0.9

sources: BID: 72339 // CNNVD: CNNVD-201501-708

SOURCES

db:CNVDid:CNVD-2015-00835
db:BIDid:72339
db:CNNVDid:CNNVD-201501-708

LAST UPDATE DATE

2022-05-17T02:09:01.103000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-00835date:2015-02-02T00:00:00
db:BIDid:72339date:2015-01-27T00:00:00
db:CNNVDid:CNNVD-201501-708date:2015-01-30T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2015-00835date:2015-01-30T00:00:00
db:BIDid:72339date:2015-01-27T00:00:00
db:CNNVDid:CNNVD-201501-708date:2015-01-30T00:00:00