PT-2002-2532 · D Link · D-Link Dwl-900Ap+ Access Point

CVE-2002-1810

·

Publicado

2002-12-31

·

Atualizado

2024-02-14

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions D-Link DWL-900AP+ Access Point versions 2.1 through 2.2
Description The issue allows remote attackers to access the TFTP server without authentication and read the config.img file. This file contains sensitive information, including the administrative password, WEP encryption keys, and network configuration information.
Recommendations For versions 2.1 and 2.2, consider restricting access to the TFTP server as a temporary workaround until a patch is available. Additionally, changing the administrative password and WEP encryption keys is recommended to minimize potential damage.

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2002-1810

Produtos afetados

D-Link Dwl-900Ap+ Access Point