PT-2020-2911 · D Link · D-Link Dir-865L

Davila Loranca

+2

·

Published

2020-06-03

·

Updated

2021-12-13

·

CVE-2020-13787

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions D-Link DIR-865L Ax version 1.20B01 Beta
Description The issue is related to the cleartext transmission of sensitive information and a vulnerability in the adv gzone.php component of the D-Link DIR-865L router's firmware, which is associated with the use of Wired Equivalent Privacy (WEP). This vulnerability can be exploited by a remote attacker to obtain the password used for the guest network.
Recommendations For D-Link DIR-865L Ax version 1.20B01 Beta, consider disabling the use of WEP encryption as a temporary workaround until a patch is available. Restrict access to the adv gzone.php component to minimize the risk of exploitation. Avoid using the guest network feature until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Cleartext Transmission of Sensitive Information

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03068
CVE-2020-13787

Affected Products

D-Link Dir-865L