CVE-2024-8461Sensitive Information Exposure in D-link Dns-320

Severity
6.9MEDIUMNVD
EPSS
1.6%
top 18.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 5

Description

A vulnerability, which was classified as problematic, was found in D-Link DNS-320 2.02b01. This affects an unknown part of the file /cgi-bin/discovery.cgi of the component Web Management Interface. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. Vendor was contacted early and confirmed that t

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5d-link/dns-3202.02b01

🔴Vulnerability Details

2
CVEList
D-Link DNS-320 Web Management Interface discovery.cgi information disclosure2024-09-05
GHSA
GHSA-97xc-8xj3-86xm: A vulnerability, which was classified as problematic, was found in D-Link DNS-320 22024-09-05
CVE-2024-8461 — Sensitive Information Exposure | cvebase