PT-2019-4309 · D Link · D-Link Dir-412

Published

2019-10-14

·

Updated

2020-08-24

·

CVE-2019-17511

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions D-Link DIR-412 version A1-1.14WW
Description The issue concerns a lack of authentication requirements for certain web interfaces on the affected router. This allows an attacker to access the router's log file through the "log get.php" API endpoint, potentially revealing the intranet network structure. The vulnerability is related to insufficient authentication in the router's firmware, which could enable a remote attacker to gain unauthorized access to protected information.
Recommendations For D-Link DIR-412 version A1-1.14WW, consider restricting access to the "log get.php" API endpoint until a patch is available. As a temporary workaround, limit access to the router's web interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00024
CVE-2019-17511

Affected Products

D-Link Dir-412