9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the data fields of page.
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 20.06 |
| Running on/with | Platform Versions |
|---|---|
Dlink Dir 615 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 20.06 |
| Running on/with | Platform Versions |
|---|---|
Dlink Dir 615 J1 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 20.06 |
| Running on/with | Platform Versions |
|---|---|
Dlink Dir 615 T1 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 20.06 |
| Running on/with | Platform Versions |
|---|---|
Dlink Dir 615jx10 | All versions |
References (4)
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.