PT-2023-4061 · D Link · D-Link Dir-895

Published

2023-07-31

·

Updated

2024-10-28

·

CVE-2023-36091

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DIR-895 version FW102b07
Description The issue is related to a function called phpcgi main in the D-Link DIR-895 router's firmware, which has weaknesses in its authentication procedure. This can be exploited by a remote attacker to gain escalated privileges. The vulnerability only affects products that are no longer supported by the maintainer.
Recommendations For D-Link DIR-895 version FW102b07, as the product is no longer supported by the maintainer, consider replacing the device with a supported model to mitigate the risk of exploitation. As a temporary workaround, restrict access to the cgibin directory and the phpcgi main function to minimize the risk of exploitation.

Fix

Incorrect Authorization

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2023-04359
CVE-2023-36091

Affected Products

D-Link Dir-895