Логотип exploitDog
bind:CVE-2023-50199
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-50199

Количество 3

Количество 3

nvd логотип

CVE-2023-50199

почти 2 года назад

D-Link G416 httpd Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link G416 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HTTP service listening on TCP port 80. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to gain access to critical functions on the device. Was ZDI-CAN-21287.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-wggh-wqhg-h7xc

почти 2 года назад

D-Link G416 httpd Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link G416 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HTTP service listening on TCP port 80. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to gain access to critical functions on the device. Was ZDI-CAN-21287.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2023-09033

больше 2 лет назад

Уязвимость httpd-демона микропрограммного обеспечения маршрутизаторов D-Link G416, позволяющая нарушителю обойти ограничения безопасности

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-50199

D-Link G416 httpd Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link G416 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HTTP service listening on TCP port 80. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to gain access to critical functions on the device. Was ZDI-CAN-21287.

CVSS3: 8.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-wggh-wqhg-h7xc

D-Link G416 httpd Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link G416 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HTTP service listening on TCP port 80. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to gain access to critical functions on the device. Was ZDI-CAN-21287.

CVSS3: 8.8
1%
Низкий
почти 2 года назад
fstec логотип
BDU:2023-09033

Уязвимость httpd-демона микропрограммного обеспечения маршрутизаторов D-Link G416, позволяющая нарушителю обойти ограничения безопасности

CVSS3: 8.8
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу