Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5wr7-m75g-xc37

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilege account) access, an attacker can intercept the response from a POST request to obtain "Admin" rights due to the admin password being displayed in XML.

An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilege account) access, an attacker can intercept the response from a POST request to obtain "Admin" rights due to the admin password being displayed in XML.

EPSS

Процентиль: 98%
0.59492
Средний

8 High

CVSS3

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 8
nvd
больше 7 лет назад

An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilege account) access, an attacker can intercept the response from a POST request to obtain "Admin" rights due to the admin password being displayed in XML.

CVSS3: 8.8
fstec
больше 7 лет назад

Уязвимость микропрограммного обеспечения маршрутизатора D-Link DIR-601, связанная с передачей критичной информации открытым текстом, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 98%
0.59492
Средний

8 High

CVSS3

Дефекты

CWE-319