Show filters
29 Total Results
Displaying 11-20 of 29
Sort by:
Attacker Value
Unknown

CVE-2017-14422

Disclosure Date: September 13, 2017 (last updated November 09, 2023)
D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices use the same hardcoded /etc/stunnel.key private key across different customers' installations, which allows remote attackers to defeat the HTTPS cryptographic protection mechanisms by leveraging knowledge of this key from another installation.
Attacker Value
Unknown

CVE-2017-14421

Disclosure Date: September 13, 2017 (last updated November 09, 2023)
D-Link DIR-850L REV. B (with firmware through FW208WWb02) devices have a hardcoded password of wrgac25_dlink.2013gui_dir850l for the Alphanetworks account upon device reset, which allows remote attackers to obtain root access via a TELNET session.
Attacker Value
Unknown

CVE-2017-14418

Disclosure Date: September 13, 2017 (last updated November 09, 2023)
The D-Link NPAPI extension, as used in conjunction with D-Link DIR-850L REV. B (with firmware through FW208WWb02) devices, sends the cleartext admin password over the Internet as part of interaction with mydlink Cloud Services.
Attacker Value
Unknown

CVE-2017-14416

Disclosure Date: September 13, 2017 (last updated November 09, 2023)
D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/web/wandetect.php.
Attacker Value
Unknown

CVE-2017-14429

Disclosure Date: September 13, 2017 (last updated November 18, 2023)
The DHCP client on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices allows unauthenticated remote code execution as root because /etc/services/INET/inet_ipv4.php mishandles shell metacharacters, affecting generated files such as WAN-1-udhcpc.sh.
Attacker Value
Unknown

CVE-2017-14423

Disclosure Date: September 13, 2017 (last updated November 09, 2023)
htdocs/parentalcontrols/bind.php on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices does not prevent unauthenticated nonce-guessing attacks, which makes it easier for remote attackers to change the DNS configuration via a series of requests.
Attacker Value
Unknown

CVE-2017-14420

Disclosure Date: September 13, 2017 (last updated November 18, 2023)
The D-Link NPAPI extension, as used on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices, does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Attacker Value
Unknown

CVE-2017-14419

Disclosure Date: September 13, 2017 (last updated November 18, 2023)
The D-Link NPAPI extension, as used on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices, participates in mydlink Cloud Services by establishing a TCP relay service for HTTP, even though a TCP relay service for HTTPS is also established.
Attacker Value
Unknown

CVE-2017-14426

Disclosure Date: September 13, 2017 (last updated November 18, 2023)
D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices have 0644 /var/etc/shadow (aka the /etc/shadow symlink target) permissions.
Attacker Value
Unknown

CVE-2017-14413

Disclosure Date: September 13, 2017 (last updated November 09, 2023)
D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/web/wpsacts.php.