CVE-2020-13783
published 2020-06-03CVE-2020-13783: D-Link DIR-865L Ax 1.20B01 Beta devices have Cleartext Storage of Sensitive Information.
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.90%
55.7th percentile
D-Link DIR-865L Ax 1.20B01 Beta devices have Cleartext Storage of Sensitive Information.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlink | dir-865l_firmware | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Unit42
6 New Vulnerabilities Found on D-Link Home Routers
blogs_unit42·2020-06-12·CVSS 8.8
[HIGH] 6 New Vulnerabilities Found on D-Link Home Routers
Threat Research Center
Threat Research
Vulnerabilities
## 6 New Vulnerabilities Found on D-Link Home Routers
Gregory Basior
Published: June 12, 2020
Threat Research
Vulnerabilities
D-Link
IoT
Wireless routers
## Executive Summary
On February 28, 2020, Palo Alto Networks’ Unit 42 researchers discovered six new vulnerabilities in D-Link wireless cloud routers running their latest firmware.
The vulnerabilities were found in the DIR-865L model of D-Link routers, which is meant for home network use. The current trend towards working from home increases the likelihood of malicious attacks against home networks, which makes it even more imperative to keeping our networking devices updated.
It is possible that some of these vulnerabilities are also present in newer models of the
Unit42
6 New Vulnerabilities Found on D-Link Home Routers
blogs_unit42·2020-06-12·CVSS 8.8
[HIGH] 6 New Vulnerabilities Found on D-Link Home Routers
## Executive Summary
On February 28, 2020, Palo Alto Networks’ Unit 42 researchers discovered six new vulnerabilities in D-Link wireless cloud routers running their latest firmware.
The vulnerabilities were found in the DIR-865L model of D-Link routers, which is meant for home network use. The current trend towards working from home increases the likelihood of malicious attacks against home networks, which makes it even more imperative to keeping our networking devices updated.
It is possible that some of these vulnerabilities are also present in newer models of the router because they share a similar codebase. The following are the six vulnerabilities found:
- - CVE-2020-13782: Improper Neutralization of Special Elements Used in a Command (Command Injection)
- CVE-2020-13786: Cross-Si
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10174https://unit42.paloaltonetworks.com/6-new-d-link-vulnerabilities-found-on-home-routers/https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10174https://unit42.paloaltonetworks.com/6-new-d-link-vulnerabilities-found-on-home-routers/
2020-06-03
Published