PT-2018-2189 · D Link · Dcm-704+1

CVE-2018-20389

·

Published

2018-12-23

·

Updated

2023-04-26

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DCM-604 versions DCM604 C1 ViaCabo 1.04 20130606 D-Link DCM-704 version EU DCM-704 1.10
Description The issue is related to a lack of protection for service data in the web interface of D-Link router firmware. It can be exploited by a remote attacker to disclose protected information using a specially crafted SNMP request. The vulnerability allows attackers to discover credentials via specific SNMP requests, including iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0.
Recommendations For D-Link DCM-604 version DCM604 C1 ViaCabo 1.04 20130606, consider restricting access to the SNMP service to minimize the risk of exploitation. For D-Link DCM-704 version EU DCM-704 1.10, avoid using the vulnerable SNMP requests iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 until the issue is resolved.

Exploit

Fix

Insufficiently Protected Credentials

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00142
CVE-2018-20389

Affected Products

Dcm-604
Dcm-704