PT-2022-23624 · D Link · D-Link G Integrated Access Device4

·

CVE-2022-36785

·

Published

2022-11-17

·

Updated

2025-04-29

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions D-Link - G integrated Access Device4 (affected versions not specified)
Description The issue concerns information disclosure and authorization bypass. It involves a file containing a URL with a private IP address and default username value "admin" in "login.asp". The web interface does not properly validate user identity variables, such as login glag and login status, allowing access without proper checking. This enables reading of admin user credentials. The vulnerability can be exploited by accessing the "setupWizard.asp" URL.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-36785

Affected Products

D-Link G Integrated Access Device4