PT-2018-2069 · D Link · D-Link Dva-5592
Luigi Gubello
·
Published
2018-07-06
·
Updated
2021-04-23
·
CVE-2018-17777
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
D-Link DVA-5592 version A1 WI 20180823
Description
An issue was discovered related to the default Parental Control PIN. If the PIN of the page "/ui/cbpc/login" is the default (0000), it is possible to bypass the login form by editing the path of the cookie
sid generated by the page. This allows an attacker to access the router control panel with administrator privileges. The vulnerability is associated with the use of the predefined PIN code and can be exploited by a remote attacker to bypass authentication and gain access to the router's control panel with administrator privileges.Recommendations
For D-Link DVA-5592 version A1 WI 20180823, consider changing the default Parental Control PIN to a unique value to prevent exploitation. As a temporary workaround, restrict access to the "/ui/cbpc/login" page to minimize the risk of unauthorized access. Avoid using the default PIN code for the
sid cookie to prevent bypassing the login form. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Improper Authentication
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dva-5592