PT-2023-2230 · D Link · D-Link Dir-882
Published
2023-03-31
·
Updated
2023-04-07
·
CVE-2023-26925
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
D-LINK DIR-882 version 1.30
Description
An information disclosure issue exists in the Syslog functionality, allowing a specially crafted network request to disclose sensitive information. This is due to a lack of protection for service data. A remote attacker can exploit this issue to reveal protected information.
Recommendations
For D-LINK DIR-882 version 1.30, consider disabling the Syslog functionality as a temporary workaround until a patch is available. Restrict access to the Syslog component to minimize the risk of exploitation.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D-Link Dir-882