PT-2013-1294 · D Link · Dsr-250+6

0_O

·

Published

2013-10-01

·

Updated

2023-04-26

·

CVE-2013-7004

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions D-Link DSR-150 versions prior to 1.08B44 D-Link DSR-150N versions prior to 1.05B64 D-Link DSR-250 versions prior to 1.08B44 D-Link DSR-250N versions prior to 1.08B44 D-Link DSR-500 versions prior to 1.08B77 D-Link DSR-500N versions prior to 1.08B77 D-Link DSR-1000 versions prior to 1.08B77 D-Link DSR-1000N versions prior to 1.08B77
Description The issue is related to a hardcoded account with administrative privileges, specifically with the username gkJ9232xXyruTRmY. This makes it easier for remote attackers to gain access by leveraging their knowledge of the username.
Recommendations For D-Link DSR-150 versions prior to 1.08B44, update the firmware to version 1.08B44 or later. For D-Link DSR-150N versions prior to 1.05B64, update the firmware to version 1.05B64 or later. For D-Link DSR-250 versions prior to 1.08B44, update the firmware to version 1.08B44 or later. For D-Link DSR-250N versions prior to 1.08B44, update the firmware to version 1.08B44 or later. For D-Link DSR-500 versions prior to 1.08B77, update the firmware to version 1.08B77 or later. For D-Link DSR-500N versions prior to 1.08B77, update the firmware to version 1.08B77 or later. For D-Link DSR-1000 versions prior to 1.08B77, update the firmware to version 1.08B77 or later. For D-Link DSR-1000N versions prior to 1.08B77, update the firmware to version 1.08B77 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2015-10245
CVE-2013-7004

Affected Products

Dsr-1000
Dsr-1000N
Dsr-150
Dsr-250
Dsr-250N
Dsr-500
Dsr-500N