PT-2019-4534 · D Link · D-Link Dir-601

Rahul Pratap Singh

·

Publicado

2019-12-26

·

Atualizado

2020-01-08

·

CVE-2019-16327

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DIR-601 B1 version 2.00NA
Description The issue is related to authentication bypass in the D-Link DIR-601 router. It does not perform authentication checks on the server side, instead relying on client-side validation, which can be bypassed. This allows a remote attacker to potentially elevate their privileges.
Recommendations For D-Link DIR-601 B1 version 2.00NA, consider disabling remote access to the device until a fix is available, as this is an end-of-life product and no official patch may be released. Restrict access to the router's administration interface to minimize the risk of exploitation.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-00574
CVE-2019-16327

Produtos afetados

D-Link Dir-601