PT-2015-3329 · D Link · D-Link Dvg-N5402Sp

·

CVE-2015-7246

·

Publicado

2015-09-01

·

Atualizado

2023-04-26

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DVG-N5402SP with firmware W1000CN-00 D-Link DVG-N5402SP with firmware W1000CN-03 D-Link DVG-N5402SP with firmware W2000EN-00
Description The issue is related to the use of default passwords for the root and tw accounts in the D-Link DVG-N5402SP router. The default password for the root account is root and for the tw account is tw. This makes it easier for remote attackers to obtain administrative access.
Recommendations For D-Link DVG-N5402SP with firmware W1000CN-00, change the default passwords for the root and tw accounts to secure ones. For D-Link DVG-N5402SP with firmware W1000CN-03, change the default passwords for the root and tw accounts to secure ones. For D-Link DVG-N5402SP with firmware W2000EN-00, change the default passwords for the root and tw accounts to secure ones.

Exploit

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02418
CVE-2015-7246

Produtos afetados

D-Link Dvg-N5402Sp