PT-2020-4209 · D Link · D-Link Dsl-2877Al+1
Published
2020-03-19
·
Updated
2023-11-17
·
CVE-2019-15656
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
D-Link DSL-2875AL and DSL-2877AL devices through 1.00.05
Description:
The issue is related to information disclosure via a crafted request to "index.asp" on the web management server. This is due to the
username v and password v variables. The vulnerability may allow a remote attacker to gain unauthorized access to protected information. The firmware of D-Link DSL-2875AL and DSL-2877AL devices is associated with unencrypted storage of credentials.Recommendations:
For D-Link DSL-2875AL and DSL-2877AL devices through 1.00.05, consider restricting access to the "index.asp" page on the web management server as a temporary workaround until a patch is available. Avoid using the
username v and password v variables in the affected API endpoint until the issue is resolved.Exploit
Fix
Cleartext Storage of Sensitive Information
Information Disclosure
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dsl-2875Al
D-Link Dsl-2877Al