ID

VAR-201708-1647


TITLE

D-Link DIR Series Router Authentication Information Disclosure Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2017-20002

DESCRIPTION

The DIR series is a series of cloud router products from D-Link. The D-LinkDIR series routers have a remote information bypass vulnerability that triggers global variables when an administrator logs in to the device. Therefore, an attacker can use this global variable to bypass security checks and use it to read arbitrary files and obtain sensitive information such as administrator account passwords.

Trust: 0.6

sources: CNVD: CNVD-2017-20002

IOT TAXONOMY

category:['IoT', 'Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-20002

AFFECTED PRODUCTS

vendor:d linkmodel:dir-815scope: - version: -

Trust: 0.6

vendor:d linkmodel:dir-868lscope: - version: -

Trust: 0.6

vendor:d linkmodel:dir-860lscope: - version: -

Trust: 0.6

vendor:d linkmodel:dir-890lscope: - version: -

Trust: 0.6

vendor:d linkmodel:dir-610lscope: - version: -

Trust: 0.6

vendor:d linkmodel:dir-822scope: - version: -

Trust: 0.6

vendor:d linkmodel:dir-600scope: - version: -

Trust: 0.6

vendor:d linkmodel:dir-850lscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2017-20002

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2017-20002
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2017-20002
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2017-20002

PATCH

title:Patch for D-LinkDIR Series Router Identity Authentication Information Disclosure Vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/99782

Trust: 0.6

sources: CNVD: CNVD-2017-20002

EXTERNAL IDS

db:CNVDid:CNVD-2017-20002

Trust: 0.6

sources: CNVD: CNVD-2017-20002

REFERENCES

url:https://blogs.securiteam.com/index.php/archives/3364

Trust: 0.6

sources: CNVD: CNVD-2017-20002

SOURCES

db:CNVDid:CNVD-2017-20002

LAST UPDATE DATE

2022-05-04T10:22:38.790000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-20002date:2017-08-10T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-20002date:2017-08-10T00:00:00