PT-2019-15178 · D Link · D-Link Dir-412

Publicado

2019-10-16

·

Atualizado

2020-08-24

·

CVE-2019-17512

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions D-Link DIR-412 A1 version 1.14WW
Description The issue concerns the presence of unauthenticated web interfaces on the affected router. An attacker can exploit this by accessing the "log clear.php" endpoint with specific parameters, such as act=clear&logtype=sysact, to clear the router's system log file. This could potentially be used to erase traces of malicious activity.
Recommendations For D-Link DIR-412 A1 version 1.14WW, as a temporary workaround, consider restricting access to the "log clear.php" endpoint to prevent unauthorized log file clearance. Additionally, avoid using the act and logtype parameters in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-17512

Produtos afetados

D-Link Dir-412