PT-2003-2209 · D Link+1 · D-Link Di-614++1
Published
2003-12-31
·
Updated
2008-09-05
·
CVE-2003-1264
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Longshine Wireless Access Point (WAP) LCS-883R-AC-B (affected versions not specified)
D-Link DI-614+ version 2.0
Description
The issue allows remote attackers to obtain the WEP secret and gain administrator privileges by downloading the configuration file (config.img) and other files without authentication. This is due to a flaw in the TFTP server.
Recommendations
For Longshine Wireless Access Point (WAP) LCS-883R-AC-B, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For D-Link DI-614+ version 2.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Di-614+
Longshine Wireless Access Point