Описание
The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the data fields of page.
Ссылки
- Broken Link
- Product
- Third Party Advisory
- Vendor Advisory
- Broken Link
- Product
- Third Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:o:dlink:dir-615_firmware:20.06:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-615:-:*:*:*:*:*:*:*
Конфигурация 2
Одновременно
cpe:2.3:o:dlink:dir-615_j1_firmware:20.06:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-615_j1:-:*:*:*:*:*:*:*
Конфигурация 3
Одновременно
cpe:2.3:o:dlink:dir-615_t1_firmware:20.06:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-615_t1:-:*:*:*:*:*:*:*
Конфигурация 4
Одновременно
cpe:2.3:o:dlink:dir-615jx10_firmware:20.06:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-615jx10:-:*:*:*:*:*:*:*
EPSS
Процентиль: 98%
0.61191
Средний
9.8 Critical
CVSS3
Дефекты
NVD-CWE-Other
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the data fields of page.
EPSS
Процентиль: 98%
0.61191
Средний
9.8 Critical
CVSS3
Дефекты
NVD-CWE-Other