PT-2018-3886 · D Link · D-Link 825L+1

Published

2018-12-20

·

Updated

2023-04-26

·

CVE-2018-18767

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link myDlink Baby App version 2.04.06 D-Link 825L firmware 1.08
Description The issue concerns the communication between the myDlink Baby App and the D-Link 825L Wi-Fi camera, where credentials, including username and password, are sent in base64 cleartext. This allows an attacker to potentially conduct a man-in-the-middle (MitM) attack on the local network to obtain these credentials. The vulnerability is also related to the use of a weak encryption mechanism in the D-Link 825L camera.
Recommendations For D-Link myDlink Baby App version 2.04.06, consider disabling the app's ability to communicate with the camera until a secure communication method is implemented. For D-Link 825L firmware 1.08, restrict access to the camera's settings and features to minimize the risk of exploitation until a firmware update with improved encryption is available. As a temporary workaround, consider using a secure, encrypted connection to protect data transmitted between the app and the camera.

Exploit

Fix

Inadequate Encryption Strength

Weakness Enumeration

Related Identifiers

BDU:2023-02829
CVE-2018-18767

Affected Products

D-Link 825L
D-Link Mydlink Baby App