PT-2019-4342 · D Link · Dir-868L+2

Publicado

2019-09-09

·

Atualizado

2021-04-23

·

CVE-2019-16190

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DIR-868L REVB versions 2.03 and earlier D-Link DIR-885L REVA versions 1.20 and earlier D-Link DIR-895L REVA versions 1.21 and earlier
Description The issue is related to the SharePort Web Access function in the firmware of D-Link routers, which has authentication weaknesses. This can be exploited by making a direct request to folder view.php or category view.php, allowing an attacker to bypass authentication. The vulnerability can be exploited remotely, potentially allowing an attacker to elevate their privileges.
Recommendations For D-Link DIR-868L REVB versions 2.03 and earlier, update to a version later than 2.03 to resolve the issue. For D-Link DIR-885L REVA versions 1.20 and earlier, update to a version later than 1.20 to resolve the issue. For D-Link DIR-895L REVA versions 1.21 and earlier, update to a version later than 1.21 to resolve the issue. As a temporary workaround, consider restricting access to folder view.php and category view.php until a patch is available.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-00060
CVE-2019-16190

Produtos afetados

Dir-868L
Dir-885L
Dir-895L