CVE-2019-17506
D-Link dir-868l_b1_firmware Missing Authentication for Critical Function
Record summary
CVE-2019-17506 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the router's username and password (and other information) via a DEVICE.ACCOUNT value for SERVICES in conjunction with AUTHORIZED_GROUP=1%0a to getcfg.php. This could be used to control the router remotely.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 17, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
dir-868l_b1_firmwareBrowse D-Link / dir-868l_b1_firmware | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALD-Link DIR-868L/817LW - Information DisclosureCVSS 9.8
D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers are vulnerable to information disclosure vulnerabilities because certain web interfaces do not require authentication. An attacker can get the router's username and password (and other information) via a DEVICE.ACCOUNT value for SERVICES in conjunction with AUTHORIZED_GROUP=1%0a to getcfg.php. This could be used to control the router remotely.
Impact
An attacker can exploit this vulnerability to gain access to sensitive information, such as router configuration settings and credentials.
Remediation
Apply the latest firmware update provided by D-Link to fix the information disclosure vulnerability.
Source: ProjectDiscovery