PT-2020-10102 · D Link · D-Link Dsl-2680

Published

2020-03-04

·

Updated

2023-04-26

·

CVE-2019-19223

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions D-Link DSL-2680 version EU 1.03
Description A Broken Access Control issue in the web administration interface allows an attacker to reboot the router by submitting a "reboot.html" GET request without being authenticated on the admin interface.
Recommendations For D-Link DSL-2680 version EU 1.03, as a temporary workaround, consider restricting access to the "reboot.html" endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

HTTP Request/Response Smuggling

XSS

Weakness Enumeration

Related Identifiers

CVE-2019-19223

Affected Products

D-Link Dsl-2680