PT-2018-3888 · D Link · D-Link Dir-895L/R+2
Kevin R
·
Published
2018-06-10
·
Updated
2023-04-26
·
CVE-2018-12103
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-890L versions 1.21B02beta01 and earlier
D-Link DIR-885L/R versions 1.21B03beta01 and earlier
D-Link DIR-895L/R versions 1.21B04beta04 and earlier
Description
The issue is related to the predictability of the "/docs/captcha (number).jpeg" URI in the administrator's panel, which can be accessed locally without authentication. This allows an attacker to disclose and manipulate CAPTCHAs, potentially leading to unauthorized login attempts to the access point. The vulnerability is associated with weaknesses in the authorization mechanism when handling the "docs/captcha (number).jpeg" file.
Recommendations
For D-Link DIR-890L versions 1.21B02beta01 and earlier, consider restricting access to the "/docs/captcha (number).jpeg" URI until a patch is available.
For D-Link DIR-885L/R versions 1.21B03beta01 and earlier, avoid using the CAPTCHA mechanism for authentication until the issue is resolved.
For D-Link DIR-895L/R versions 1.21B04beta04 and earlier, as a temporary workaround, consider disabling the CAPTCHA feature to minimize the risk of exploitation.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D-Link Dir-885L
D-Link Dir-890L
D-Link Dir-895L/R