CVE-2018-17777

Severity
9.8CRITICAL
EPSS
0.6%
top 31.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 18
Latest updateMay 13

Description

An issue was discovered on D-Link DVA-5592 A1_WI_20180823 devices. If the PIN of the page "/ui/cbpc/login" is the default Parental Control PIN (0000), it is possible to bypass the login form by editing the path of the cookie "sid" generated by the page. The attacker will have access to the router control panel with administrator privileges.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

NVDdlink/dva-5592_firmwarea1_wi_20180823

🔴Vulnerability Details

2
GHSA
GHSA-r292-8vw9-293g: An issue was discovered on D-Link DVA-5592 A1_WI_20180823 devices2022-05-13
CVEList
CVE-2018-17777: An issue was discovered on D-Link DVA-5592 A1_WI_20180823 devices2018-12-18