ID

VAR-201910-1856


TITLE

DLink DIR-878 has arbitrary file reading vulnerability

Trust: 0.6

sources: CNVD: CNVD-2019-30494

DESCRIPTION

DIR-878 adopts IEEE802.11ac WAVE 2 wireless technology, and MU-MIMO technology for simultaneous multi-person networking, dual-band wireless transmission / reception up to 1900Mbps, low-interference, transmission rate up to 1300Mbps 5GHz band wireless network environment. DLink DIR-878 has an arbitrary file reading vulnerability. An attacker could use the vulnerability to read arbitrary file sensitive information.

Trust: 0.6

sources: CNVD: CNVD-2019-30494

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2019-30494

AFFECTED PRODUCTS

vendor:d link electronic equipmentmodel:dlink dir-869scope:eqversion:v1.0.2

Trust: 0.6

sources: CNVD: CNVD-2019-30494

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2019-30494
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2019-30494
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2019-30494

PATCH

title:DLink dir-869 has arbitrary file reading vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/178647

Trust: 0.6

sources: CNVD: CNVD-2019-30494

EXTERNAL IDS

db:CNVDid:CNVD-2019-30494

Trust: 0.6

sources: CNVD: CNVD-2019-30494

SOURCES

db:CNVDid:CNVD-2019-30494

LAST UPDATE DATE

2022-05-04T10:21:54.116000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-30494date:2019-10-16T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2019-30494date:2019-10-15T00:00:00