PT-2022-23624 · D Link · D-Link G Integrated Access Device4

Metadata

·

Published

2022-11-17

·

Updated

2025-04-29

·

CVE-2022-36785

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions D-Link - G integrated Access Device4 (affected versions not specified)
Description The issue concerns information disclosure and authorization bypass. It involves a file containing a URL with a private IP address and default username value "admin" in "login.asp". The web interface does not properly validate user identity variables, such as login glag and login status, allowing access without proper checking. This enables reading of admin user credentials. The vulnerability can be exploited by accessing the "setupWizard.asp" URL.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-36785

Affected Products

D-Link G Integrated Access Device4