PT-2020-10375 · D Link · D-Link Dir-859
Miguel Mendez Z
+3
·
Published
2020-01-02
·
Updated
2021-07-21
·
CVE-2019-20213
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-859 versions prior to 1.07b03 beta
Description
The issue allows for unauthenticated information disclosure. This can be achieved by using the
AUTHORIZED GROUP=1%0a value, as demonstrated in the vpnconfig.php file.Recommendations
For versions prior to 1.07b03 beta, update to version 1.07b03 beta or later to resolve the issue. As a temporary workaround, consider restricting access to the
vpnconfig.php file to minimize the risk of exploitation.Exploit
Fix
Incorrect Authorization
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dir-859