PT-2020-10375 · D Link · D-Link Dir-859

Miguel Mendez Z

+3

·

Published

2020-01-02

·

Updated

2021-07-21

·

CVE-2019-20213

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions D-Link DIR-859 versions prior to 1.07b03 beta
Description The issue allows for unauthenticated information disclosure. This can be achieved by using the AUTHORIZED GROUP=1%0a value, as demonstrated in the vpnconfig.php file.
Recommendations For versions prior to 1.07b03 beta, update to version 1.07b03 beta or later to resolve the issue. As a temporary workaround, consider restricting access to the vpnconfig.php file to minimize the risk of exploitation.

Exploit

Fix

Incorrect Authorization

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20213

Affected Products

D-Link Dir-859