Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cpvj-qfc6-rjvx

Опубликовано: 21 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.6

Описание

An unauthenticated Local File Inclusion (LFI) vulnerability in D-Link DSR series routers allows remote attackers to retrieve sensitive configuration files in clear text. The exposed files contain administrative credentials, VPN settings, and other sensitive information, enabling full administrative access to the router. Affected Products include: DSR-150, DSR-150N, and DSR-250N v1.09B32_WW.

An unauthenticated Local File Inclusion (LFI) vulnerability in D-Link DSR series routers allows remote attackers to retrieve sensitive configuration files in clear text. The exposed files contain administrative credentials, VPN settings, and other sensitive information, enabling full administrative access to the router. Affected Products include: DSR-150, DSR-150N, and DSR-250N v1.09B32_WW.

EPSS

Процентиль: 95%
0.10268
Средний

6.6 Medium

CVSS3

Дефекты

CWE-200
CWE-24

Связанные уязвимости

CVSS3: 8.6
nvd
10 месяцев назад

A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attackers to manipulate input parameters used for file or directory path resolution (e.g., via sequences such as “../”). Successful exploitation may allow access to files outside of the intended directory, potentially exposing sensitive system or configuration files. The issue results from insufficient validation or sanitization of user-supplied input. Affected Products include: DSR-150, DSR-150N, and DSR-250N v1.09B32_WW.

CVSS3: 10
fstec
10 месяцев назад

Уязвимость компонента Setting Handler микропрограммного обеспечения маршрутизаторов D-Link DSR-150, DSR-150N и DSR-250, позволяющая нарушителю получить полный доступ к устройствам

EPSS

Процентиль: 95%
0.10268
Средний

6.6 Medium

CVSS3

Дефекты

CWE-200
CWE-24