Record summary

CVE-2019-17506 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the router's username and password (and other information) via a DEVICE.ACCOUNT value for SERVICES in conjunction with AUTHORIZED_GROUP=1%0a to getcfg.php. This could be used to control the router remotely.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 17, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALD-Link DIR-868L/817LW - Information DisclosureCVSS 9.8

D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers are vulnerable to information disclosure vulnerabilities because certain web interfaces do not require authentication. An attacker can get the router's username and password (and other information) via a DEVICE.ACCOUNT value for SERVICES in conjunction with AUTHORIZED_GROUP=1%0a to getcfg.php. This could be used to control the router remotely.

Impact

An attacker can exploit this vulnerability to gain access to sensitive information, such as router configuration settings and credentials.

Remediation

Apply the latest firmware update provided by D-Link to fix the information disclosure vulnerability.

WeaknessesCWE-306
Authorspikpikcu
Template tagscvecve2019dlinkrouterdisclosurevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:dlink:dir-868l_b1_firmware:2.03:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2