PT-2022-2079 · D Link · D-Link Dir-850L
Published
2022-03-04
·
Updated
2022-09-09
·
CVE-2021-46378
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-850 versions ET850-1.08TRb03
Description
The issue is related to errors in loading configuration files in the D-Link DIR-850 router's firmware. It allows a remote attacker to redirect users to an arbitrary URL due to an incorrect access control vulnerability. This can be exploited through an unauthenticated remote configuration download.
Recommendations
For version ET850-1.08TRb03, update the firmware to a version that addresses the incorrect access control vulnerability.
As a temporary workaround, consider restricting access to the configuration download feature to minimize the risk of exploitation.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dir-850L