PT-2024-10145 · D Link · D-Link Dir-816 A2

Yhryhryhr_Tu

·

Published

2024-12-30

·

Updated

2025-01-02

·

CVE-2024-13108

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions D-Link DIR-816 A2 version 1.10CNB05 R1B011D88210
Description A critical issue is present in the D-Link DIR-816 A2, related to inadequate access controls in the /goform/form2NetSniper.cgi file. This can be exploited remotely by sending a specially crafted HTTP POST request, potentially allowing an attacker to gain unauthorized access to protected information. The exploit has been disclosed publicly.
Recommendations For D-Link DIR-816 A2 version 1.10CNB05 R1B011D88210, consider disabling access to the /goform/form2NetSniper.cgi file as a temporary workaround until a patch is available. Restrict access to this file to minimize the risk of exploitation. Avoid using this file in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

BDU:2025-00426
CVE-2024-13108

Affected Products

D-Link Dir-816 A2