PT-2020-2911 · D Link · D-Link Dir-865L
Davila Loranca
+2
·
Published
2020-06-03
·
Updated
2021-12-13
·
CVE-2020-13787
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-865L Ax version 1.20B01 Beta
Description
The issue is related to the cleartext transmission of sensitive information and a vulnerability in the adv gzone.php component of the D-Link DIR-865L router's firmware, which is associated with the use of Wired Equivalent Privacy (WEP). This vulnerability can be exploited by a remote attacker to obtain the password used for the guest network.
Recommendations
For D-Link DIR-865L Ax version 1.20B01 Beta, consider disabling the use of WEP encryption as a temporary workaround until a patch is available. Restrict access to the adv gzone.php component to minimize the risk of exploitation. Avoid using the guest network feature until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Cleartext Transmission of Sensitive Information
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dir-865L