CVE-2015-7247
published 2017-04-24CVE-2015-7247: D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and web account hashes (super and admin)…
PriorityP264critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
10.15%
95.1th percentile
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and web account hashes (super and admin) in plaintext when running a configuration backup, which allows remote attackers to obtain sensitive information.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-link | dvg-n5402sp_firmware | — | — |
| d-link | dvg-n5402sp_firmware | — | — |
| d-link | dvg-n5402sp_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
commandgetpage=html%2Findex.html&errorpage=../../../../../../../../../../../etc/shadow&var%3Amenu=setup&var%3Apage=connected&objaction=auth&%3Ausername=blah&%3Apassword=blah&%3Aaction=login&%3Asessionid=abcdefgh↗
- →Detect path traversal attempts via the 'errorpage' POST parameter targeting /cgi-bin/webproc on port 8080 ↗
- →Alert on POST requests to /cgi-bin/webproc containing 'errorpage' parameter with directory traversal sequences (e.g., '../') ↗
- →Monitor for configuration backup downloads by the restricted 'support' user account, which can expose cleartext admin credentials ↗
- →Detect use of default credentials root:root or tw:tw on Telnet service of D-Link DVG-N5402SP devices ↗
- →Flag HTTP responses from /cgi-bin/webproc on port 8080 that set a new sessionid cookie alongside /etc/shadow content in the body ↗
- ·Vulnerability affects only specific firmware versions; detections should be scoped to those versions ↗
- ·CVE-2015-7247 (sensitive info leakage via config backup) is distinct from CVE-2015-7245 (path traversal) and CVE-2015-7246 (hardcoded credentials); all three share the same exploit report ↗
- ·Cleartext credential exposure in config backup affects web account hashes for both 'super' and 'admin' accounts, not just lower-privilege users ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/135590/D-Link-DVG-N5402SP-Path-Traversal-Information-Disclosure.htmlhttp://seclists.org/fulldisclosure/2016/Feb/24https://www.exploit-db.com/exploits/39409/http://packetstormsecurity.com/files/135590/D-Link-DVG-N5402SP-Path-Traversal-Information-Disclosure.htmlhttp://seclists.org/fulldisclosure/2016/Feb/24https://www.exploit-db.com/exploits/39409/
2017-04-24
Published