CVE-2019-15655

HIGH

Dlink Dsl-2875al Firmware < 1.00.05 - Missing Authentication

Title source: rule

Description

D-Link DSL-2875AL devices through 1.00.05 are prone to password disclosure via a simple crafted /romfile.cfg request to the web management server. This request doesn't require any authentication and will lead to saving the configuration file. The password is stored in cleartext.

Scores

CVSS v3 7.5
EPSS 0.0131
EPSS Percentile 79.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-522 CWE-306
Status published

Affected Products (1)

dlink/dsl-2875al_firmware < 1.00.05

Timeline

Published Mar 19, 2020
Tracked Since Feb 18, 2026