PT-2020-14692 · D Link · D-Link Dir-816L

CVE-2020-15894

·

Published

2020-07-22

·

Updated

2023-11-08

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions D-Link DIR-816L devices versions 2.x before 1.10b04Beta02
Description An issue exists where an exposed administration function in "getcfg.php" can be used to call various services, potentially allowing an attacker to retrieve sensitive information, such as admin login credentials, by manipulating the POST SERVICES variable in the query string to DEVICE.ACCOUNT.
Recommendations For D-Link DIR-816L devices versions 2.x before 1.10b04Beta02, update to version 1.10b04Beta02 or later to resolve the issue. As a temporary workaround, consider restricting access to the "getcfg.php" file to minimize the risk of exploitation. Avoid using the POST SERVICES variable in the affected API endpoint until the issue is resolved.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15894

Affected Products

D-Link Dir-816L