Severity
7.5HIGH
EPSS
1.3%
top 20.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 22
Latest updateMay 24

Description

An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. There exists an exposed administration function in getcfg.php, which can be used to call various services. It can be utilized by an attacker to retrieve various sensitive information, such as admin login credentials, by setting the value of _POST_SERVICES in the query string to DEVICE.ACCOUNT.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

NVDdlink/dir-816l_firmware2.06, 2.06.b09+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4xhc-v448-j5jx: An issue was discovered on D-Link DIR-816L devices 22022-05-24
CVEList
CVE-2020-15894: An issue was discovered on D-Link DIR-816L devices 22020-07-22
CVE-2020-15894 (HIGH CVSS 7.5) | An issue was discovered on D-Link D | cvebase.io