CVE-2020-9376
D-Link DIR-610 Devices - Information Disclosure
Record summary
CVE-2020-9376 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
D-Link DIR-610 devices allow Information Disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Exploitation context
Proofs of concept
1Repository PoCs
GitHubrenatoalencar/dlink-dir610-exploitsRepository PoCby renatoalencarStars: 4Not analyzed3 files
Nuclei templates
1ProjectDiscoveryHIGHD-Link DIR-610 Devices - Information DisclosureCVSS 7.5
D-Link DIR-610 devices allow information disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Impact
An attacker can gain sensitive information from the device, leading to potential unauthorized access or further attacks.
Remediation
Apply the latest firmware update provided by D-Link to fix the vulnerability.
Source: ProjectDiscovery