Record summary

CVE-2020-9376 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

D-Link DIR-610 devices allow Information Disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

Proofs of concept

1

Repository PoCs

GitHubrenatoalencar/dlink-dir610-exploitsRepository PoCby renatoalencarStars: 4Not analyzed3 files

1.2 KiB · linked to 2 vulnerabilities

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHD-Link DIR-610 Devices - Information DisclosureCVSS 7.5

D-Link DIR-610 devices allow information disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Impact

An attacker can gain sensitive information from the device, leading to potential unauthorized access or further attacks.

Remediation

Apply the latest firmware update provided by D-Link to fix the vulnerability.

WeaknessesCWE-74
Authorswhynotke
Template tagscvecve2020dlinkdisclosureroutervuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:o:dlink:dir-610_firmware:-:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

4