PT-2020-4209 · D Link · D-Link Dsl-2877Al+1

Published

2020-03-19

·

Updated

2023-11-17

·

CVE-2019-15656

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: D-Link DSL-2875AL and DSL-2877AL devices through 1.00.05
Description: The issue is related to information disclosure via a crafted request to "index.asp" on the web management server. This is due to the username v and password v variables. The vulnerability may allow a remote attacker to gain unauthorized access to protected information. The firmware of D-Link DSL-2875AL and DSL-2877AL devices is associated with unencrypted storage of credentials.
Recommendations: For D-Link DSL-2875AL and DSL-2877AL devices through 1.00.05, consider restricting access to the "index.asp" page on the web management server as a temporary workaround until a patch is available. Avoid using the username v and password v variables in the affected API endpoint until the issue is resolved.

Exploit

Fix

Cleartext Storage of Sensitive Information

Information Disclosure

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BDU:2020-04644
CVE-2019-15656

Affected Products

D-Link Dsl-2875Al
D-Link Dsl-2877Al