PT-2023-6407 · D Link · Dsl-2730U+1

Amey Chavekar

+2

·

Published

2023-10-19

·

Updated

2024-09-12

·

CVE-2023-46033

CVSS v2.0

7.7

High

VectorAV:A/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link (Non-US) DSL-2750U N300 ADSL2+ and (Non-US) DSL-2730U N150 ADSL2+ (affected versions not specified)
Description The issue is related to Incorrect Access Control in the D-Link routers. The UART/Serial interface on the PCB provides log output and a root terminal without proper access control, which can be exploited by an attacker to bypass access restrictions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2023-07121
CVE-2023-46033

Affected Products

Dsl-2730U
Dsl-2750U