cbcvebase.
CVE-2015-7247
published 2017-04-24

CVE-2015-7247: D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and web account hashes (super and admin)…

PriorityP264critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
10.15%
95.1th percentile
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and web account hashes (super and admin) in plaintext when running a configuration backup, which allows remote attackers to obtain sensitive information.

Affected

3 ranges
VendorProductVersion rangeFixed in
d-linkdvg-n5402sp_firmware
d-linkdvg-n5402sp_firmware
d-linkdvg-n5402sp_firmware

Detection & IOCsextracted from sources · hover to see the quote

path/cgi-bin/webproc
port8080
commandgetpage=html%2Findex.html&errorpage=../../../../../../../../../../../etc/shadow&var%3Amenu=setup&var%3Apage=connected&obj­action=auth&%3Ausername=blah&%3Apassword=blah&%3Aaction=login&%3Asessionid=abcdefgh
path../../../../../../../../../../../etc/shadow
  • Detect path traversal attempts via the 'errorpage' POST parameter targeting /cgi-bin/webproc on port 8080
  • Alert on POST requests to /cgi-bin/webproc containing 'errorpage' parameter with directory traversal sequences (e.g., '../')
  • Monitor for configuration backup downloads by the restricted 'support' user account, which can expose cleartext admin credentials
  • Detect use of default credentials root:root or tw:tw on Telnet service of D-Link DVG-N5402SP devices
  • Flag HTTP responses from /cgi-bin/webproc on port 8080 that set a new sessionid cookie alongside /etc/shadow content in the body
  • ·Vulnerability affects only specific firmware versions; detections should be scoped to those versions
  • ·CVE-2015-7247 (sensitive info leakage via config backup) is distinct from CVE-2015-7245 (path traversal) and CVE-2015-7246 (hardcoded credentials); all three share the same exploit report
  • ·Cleartext credential exposure in config backup affects web account hashes for both 'super' and 'admin' accounts, not just lower-privilege users

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.