Show filters
24 Total Results
Displaying 21-24 of 24
Sort by:
Attacker Value
Unknown

CVE-2019-13265

Disclosure Date: August 27, 2019 (last updated November 27, 2024)
D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. They forward ARP requests, which are sent as broadcast packets, between the host and the guest networks. To use this leakage as a direct covert channel, the sender can trivially issue an ARP request to an arbitrary computer on the network. (In general, some routers restrict ARP forwarding only to requests destined for the network's subnet mask, but these routers did not restrict this traffic in any way. Depending on this factor, one must use either the lower 8 bits of the IP address, or the entire 32 bits, as the data payload.)
Attacker Value
Unknown

CVE-2019-9122

Disclosure Date: February 25, 2019 (last updated November 27, 2024)
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the ntp_server parameter in an ntp_sync.cgi POST request.
Attacker Value
Unknown

CVE-2019-9126

Disclosure Date: February 25, 2019 (last updated November 09, 2023)
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. There is an information disclosure vulnerability via requests for the router_info.xml document. This will reveal the PIN code, MAC address, routing table, firmware version, update time, QOS information, LAN information, and WLAN information of the device.
Attacker Value
Unknown

CVE-2019-9123

Disclosure Date: February 25, 2019 (last updated November 09, 2023)
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. The "user" account has a blank password.