Описание
D-Link DIR-610 devices allow Information Disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Ссылки
- ExploitPatchThird Party Advisory
- ExploitVendor Advisory
- ProductVendor Advisory
- ExploitPatchThird Party Advisory
- ExploitVendor Advisory
- ProductVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:o:dlink:dir-610_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-610:-:*:*:*:*:*:*:*
EPSS
Процентиль: 100%
0.92258
Критический
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-74
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
** UNSUPPORTED WHEN ASSIGNED ** D-Link DIR-610 devices allow Information Disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
EPSS
Процентиль: 100%
0.92258
Критический
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-74