PT-2025-3539 · D Link · D-Link Dir-816

Published

2024-12-30

·

Updated

2025-01-18

·

CVE-2024-57682

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions D-Link DIR-816A2 versions 1.10CNB05 R1B011D88210
Description The issue is related to an information disclosure vulnerability in the d status.asp component. This vulnerability can be exploited by an unauthenticated attacker using a specially crafted HTTP POST request to gain unauthorized access to sensitive information.
Recommendations For version 1.10CNB05 R1B011D88210, consider disabling access to the d status.asp component until a patch is available to prevent exploitation. Restrict access to sensitive information to minimize the risk of unauthorized disclosure.

Fix

Missing Authorization

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2025-01521
CVE-2024-57682

Affected Products

D-Link Dir-816