PT-2024-10145 · D Link · D-Link Dir-816 A2
Yhryhryhr_Tu
·
Published
2024-12-30
·
Updated
2025-01-02
·
CVE-2024-13108
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-816 A2 version 1.10CNB05 R1B011D88210
Description
A critical issue is present in the D-Link DIR-816 A2, related to inadequate access controls in the /goform/form2NetSniper.cgi file. This can be exploited remotely by sending a specially crafted HTTP POST request, potentially allowing an attacker to gain unauthorized access to protected information. The exploit has been disclosed publicly.
Recommendations
For D-Link DIR-816 A2 version 1.10CNB05 R1B011D88210, consider disabling access to the /goform/form2NetSniper.cgi file as a temporary workaround until a patch is available. Restrict access to this file to minimize the risk of exploitation. Avoid using this file in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Access Control
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dir-816 A2