Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cpvj-qfc6-rjvx

Опубликовано: 21 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.6

Описание

An unauthenticated Local File Inclusion (LFI) vulnerability in D-Link DSR series routers allows remote attackers to retrieve sensitive configuration files in clear text. The exposed files contain administrative credentials, VPN settings, and other sensitive information, enabling full administrative access to the router. Affected Products include: DSR-150, DSR-150N, and DSR-250N v1.09B32_WW.

An unauthenticated Local File Inclusion (LFI) vulnerability in D-Link DSR series routers allows remote attackers to retrieve sensitive configuration files in clear text. The exposed files contain administrative credentials, VPN settings, and other sensitive information, enabling full administrative access to the router. Affected Products include: DSR-150, DSR-150N, and DSR-250N v1.09B32_WW.

EPSS

Процентиль: 20%
0.00064
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.6
nvd
4 месяца назад

An unauthenticated Local File Inclusion (LFI) vulnerability in D-Link DSR series routers allows remote attackers to retrieve sensitive configuration files in clear text. The exposed files contain administrative credentials, VPN settings, and other sensitive information, enabling full administrative access to the router. Affected Products include: DSR-150, DSR-150N, and DSR-250N v1.09B32_WW.

CVSS3: 10
fstec
4 месяца назад

Уязвимость компонента Setting Handler микропрограммного обеспечения маршрутизаторов D-Link DSR-150, DSR-150N и DSR-250, позволяющая нарушителю получить полный доступ к устройствам

EPSS

Процентиль: 20%
0.00064
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-200