PT-2023-2230 · D Link · D-Link Dir-882

CVE-2023-26925

·

Published

2023-03-31

·

Updated

2023-04-07

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions D-LINK DIR-882 version 1.30
Description An information disclosure issue exists in the Syslog functionality, allowing a specially crafted network request to disclose sensitive information. This is due to a lack of protection for service data. A remote attacker can exploit this issue to reveal protected information.
Recommendations For D-LINK DIR-882 version 1.30, consider disabling the Syslog functionality as a temporary workaround until a patch is available. Restrict access to the Syslog component to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-01984
CVE-2023-26925

Affected Products

D-Link Dir-882