Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mr7p-fqx6-72v7

Опубликовано: 16 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The application's 'Login' endpoint returns distinct JSON responses depending on whether the supplied username is associated with an existing account. Because the responses differ in the error.messagestring value, an unauthenticated remote attacker can enumerate valid usernames/accounts on the server. NOTE: D-Link states that a fix is under development.

D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The application's 'Login' endpoint returns distinct JSON responses depending on whether the supplied username is associated with an existing account. Because the responses differ in the error.messagestring value, an unauthenticated remote attacker can enumerate valid usernames/accounts on the server. NOTE: D-Link states that a fix is under development.

EPSS

Процентиль: 15%
0.0005
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-204

Связанные уязвимости

CVSS3: 5.3
nvd
4 месяца назад

D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The application's 'Login' endpoint returns distinct JSON responses depending on whether the supplied username is associated with an existing account. Because the responses differ in the `error.message`string value, an unauthenticated remote attacker can enumerate valid usernames/accounts on the server. NOTE: D-Link states that a fix is under development.

CVSS3: 5.3
fstec
4 месяца назад

Уязвимость программного обеспечения для централизованного управления беспроводными сетями D-Link Nuclias Connect, связанная с несоответствием ответов на входящие запросы, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 15%
0.0005
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-204