PT-2002-2532 · D Link · D-Link Dwl-900Ap+ Access Point
Published
2002-12-31
·
Updated
2024-02-14
·
CVE-2002-1810
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
D-Link DWL-900AP+ Access Point versions 2.1 through 2.2
Description
The issue allows remote attackers to access the TFTP server without authentication and read the config.img file. This file contains sensitive information, including the administrative password, WEP encryption keys, and network configuration information.
Recommendations
For versions 2.1 and 2.2, consider restricting access to the TFTP server as a temporary workaround until a patch is available. Additionally, changing the administrative password and WEP encryption keys is recommended to minimize potential damage.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D-Link Dwl-900Ap+ Access Point