PT-2013-1295 · D Link · Dsr-250+6

0_O

·

Published

2013-10-01

·

Updated

2023-04-26

·

CVE-2013-7005

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions D-Link DSR-150 versions prior to 1.08B44 D-Link DSR-150N versions prior to 1.05B64 D-Link DSR-250 versions prior to 1.08B44 D-Link DSR-250N versions prior to 1.08B44 D-Link DSR-500 versions prior to 1.08B77 D-Link DSR-500N versions prior to 1.08B77 D-Link DSR-1000 versions prior to 1.08B77 D-Link DSR-1000N versions prior to 1.08B77
Description The issue allows local users to obtain sensitive information by reading the Users[#]["Password"] fields in the "/tmp/teamf1.cfg.ascii" file, as account passwords are stored in cleartext. This affects the file system of the D-Link DSR routers, where user passwords are stored in open form in the /tmp/teamf1.cfg.ascii file.
Recommendations For D-Link DSR-150 versions prior to 1.08B44, update the firmware to version 1.08B44 or later. For D-Link DSR-150N versions prior to 1.05B64, update the firmware to version 1.05B64 or later. For D-Link DSR-250 versions prior to 1.08B44, update the firmware to version 1.08B44 or later. For D-Link DSR-250N versions prior to 1.08B44, update the firmware to version 1.08B44 or later. For D-Link DSR-500 versions prior to 1.08B77, update the firmware to version 1.08B77 or later. For D-Link DSR-500N versions prior to 1.08B77, update the firmware to version 1.08B77 or later. For D-Link DSR-1000 versions prior to 1.08B77, update the firmware to version 1.08B77 or later. For D-Link DSR-1000N versions prior to 1.08B77, update the firmware to version 1.08B77 or later.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2015-10247
CVE-2013-7005

Affected Products

Dsr-1000
Dsr-1000N
Dsr-150
Dsr-250
Dsr-250N
Dsr-500
Dsr-500N