Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Nguyen Van Chung

#16244of 56,330
17.6Total CVSS
Vulnerabilities · 2
High
2
PT-2019-15883
8.8
2019-12-05
D Link · Dap-1860 · CVE-2019-19597
**Name of the Vulnerable Software and Affected Versions** D-Link DAP-1860 versions prior to v1.04b03 Beta **Description** The issue allows for arbitrary remote code execution as root without authentication. This is achieved via shell metacharacters within an HNAP AUTH HTTP header. **Recommendations** For versions prior to v1.04b03 Beta, update to v1.04b03 Beta or later to resolve the issue.
PT-2019-15884
8.8
2019-12-05
D Link · D-Link Dap-1860 · CVE-2019-19598
**Name of the Vulnerable Software and Affected Versions** D-Link DAP-1860 versions prior to v1.04b03 Beta **Description** The issue allows access to administrator functions without authentication by manipulating the HNAP AUTH header timestamp value in HTTP requests. This value is compared to the one stored in the device's /var/hnap/timestamp file. If the two values match, the request passes the authentication check. **Recommendations** For versions prior to v1.04b03 Beta, update to version v1.04b03 Beta or later to resolve the issue. As a temporary workaround, consider restricting access to the device's administrator functions until the update can be applied.