PT-2019-4309 · D Link · D-Link Dir-412

Publicado

2019-10-14

·

Atualizado

2020-08-24

·

CVE-2019-17511

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions D-Link DIR-412 version A1-1.14WW
Description The issue concerns a lack of authentication requirements for certain web interfaces on the affected router. This allows an attacker to access the router's log file through the "log get.php" API endpoint, potentially revealing the intranet network structure. The vulnerability is related to insufficient authentication in the router's firmware, which could enable a remote attacker to gain unauthorized access to protected information.
Recommendations For D-Link DIR-412 version A1-1.14WW, consider restricting access to the "log get.php" API endpoint until a patch is available. As a temporary workaround, limit access to the router's web interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-00024
CVE-2019-17511

Produtos afetados

D-Link Dir-412