PT-2019-15884 · D Link · D-Link Dap-1860

Nguyen Van Chung

·

Published

2019-12-05

·

Updated

2019-12-14

·

CVE-2019-19598

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DAP-1860 versions prior to v1.04b03 Beta
Description The issue allows access to administrator functions without authentication by manipulating the HNAP AUTH header timestamp value in HTTP requests. This value is compared to the one stored in the device's /var/hnap/timestamp file. If the two values match, the request passes the authentication check.
Recommendations For versions prior to v1.04b03 Beta, update to version v1.04b03 Beta or later to resolve the issue. As a temporary workaround, consider restricting access to the device's administrator functions until the update can be applied.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-19598

Affected Products

D-Link Dap-1860