PT-2020-4209 · D Link · D-Link Dsl-2877Al+1

CVE-2019-15656

·

Published

2020-03-19

·

Updated

2023-11-17

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: D-Link DSL-2875AL and DSL-2877AL devices through 1.00.05
Description: The issue is related to information disclosure via a crafted request to "index.asp" on the web management server. This is due to the username v and password v variables. The vulnerability may allow a remote attacker to gain unauthorized access to protected information. The firmware of D-Link DSL-2875AL and DSL-2877AL devices is associated with unencrypted storage of credentials.
Recommendations: For D-Link DSL-2875AL and DSL-2877AL devices through 1.00.05, consider restricting access to the "index.asp" page on the web management server as a temporary workaround until a patch is available. Avoid using the username v and password v variables in the affected API endpoint until the issue is resolved.

Exploit

Fix

Cleartext Storage of Sensitive Information

Information Disclosure

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04644
CVE-2019-15656

Affected Products

D-Link Dsl-2875Al
D-Link Dsl-2877Al