PT-2019-6346 · D Link · D-Link Dir-878
Published
2019-02-25
·
Updated
2023-04-26
·
CVE-2019-9124
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-878 version 1.12B01
Description
An issue was discovered that allows an attacker to log in with a blank password at the /HNAP1 URI. The vulnerability is related to weaknesses in the HNAP1 protocol implementation, specifically in the authentication procedure. This can allow a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations
For D-Link DIR-878 version 1.12B01, as a temporary workaround, consider restricting access to the /HNAP1 URI until a patch is available. Avoid using blank passwords for authentication in the affected device.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D-Link Dir-878