Vulnerability Description
D-Link DGS-1100 devices with Rev.B firmware 1.01.018 have a hardcoded SSL private key, which allows man-in-the-middle attackers to spoof devices by hijacking an HTTPS session.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dgs-1100 Firmware | 1.01.018 |
| Dlink | Dgs-1100-05 | - |
| Dlink | Dgs-1100-05Pd | - |
| Dlink | Dgs-1100-08 | - |
| Dlink | Dgs-1100-08P | - |
| Dlink | Dgs-1100-10Mp | - |
| Dlink | Dgs-1100-10Mpp | - |
| Dlink | Dgs-1100-16 | - |
| Dlink | Dgs-1100-18 | - |
| Dlink | Dgs-1100-24 | - |
| Dlink | Dgs-1100-24P | - |
| Dlink | Dgs-1100-26 | - |
| Dlink | Dgs-1100-26Mp | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/95329
- https://labs.integrity.pt/advisories/dlink-dgs-1100-hardcoded-keys/ExploitMitigationThird Party Advisory
- http://www.securityfocus.com/bid/95329
- https://labs.integrity.pt/advisories/dlink-dgs-1100-hardcoded-keys/ExploitMitigationThird Party Advisory
FAQ
What is CVE-2016-10125?
CVE-2016-10125 is a vulnerability with a CVSS score of 8.1 (HIGH). D-Link DGS-1100 devices with Rev.B firmware 1.01.018 have a hardcoded SSL private key, which allows man-in-the-middle attackers to spoof devices by hijacking an HTTPS session.
How severe is CVE-2016-10125?
CVE-2016-10125 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-10125?
Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dgs-1100 Firmware, Dlink Dgs-1100-05, Dlink Dgs-1100-05Pd, Dlink Dgs-1100-08, Dlink Dgs-1100-08P.