PT-2018-2189 · D Link · Dcm-704+1
Published
2018-12-23
·
Updated
2023-04-26
·
CVE-2018-20389
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
D-Link DCM-604 versions DCM604 C1 ViaCabo 1.04 20130606
D-Link DCM-704 version EU DCM-704 1.10
Description
The issue is related to a lack of protection for service data in the web interface of D-Link router firmware. It can be exploited by a remote attacker to disclose protected information using a specially crafted SNMP request. The vulnerability allows attackers to discover credentials via specific SNMP requests, including
iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0.Recommendations
For D-Link DCM-604 version DCM604 C1 ViaCabo 1.04 20130606, consider restricting access to the SNMP service to minimize the risk of exploitation.
For D-Link DCM-704 version EU DCM-704 1.10, avoid using the vulnerable SNMP requests
iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 until the issue is resolved.Exploit
Fix
Insufficiently Protected Credentials
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dcm-604
Dcm-704