Vulnerability Description
D-Link DIR-615 before v20.12PTb04 has a second admin account with a 0x1 BACKDOOR value, which might allow remote attackers to obtain access via a TELNET connection.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dir-615 | <= 20.12ptb01 |
Related Weaknesses (CWE)
References
- ftp://ftp2.dlink.com/SECURITY_ADVISEMENTS/DIR-615/REVT/DIR-615_REVT_RELEASE_NOTERelease NotesVendor Advisory
- http://www.rootlabs.com.br/backdoor-dlink-dir-615/Third Party Advisory
- ftp://ftp2.dlink.com/SECURITY_ADVISEMENTS/DIR-615/REVT/DIR-615_REVT_RELEASE_NOTERelease NotesVendor Advisory
- http://www.rootlabs.com.br/backdoor-dlink-dir-615/Third Party Advisory
FAQ
What is CVE-2017-11436?
CVE-2017-11436 is a vulnerability with a CVSS score of 9.8 (CRITICAL). D-Link DIR-615 before v20.12PTb04 has a second admin account with a 0x1 BACKDOOR value, which might allow remote attackers to obtain access via a TELNET connection.
How severe is CVE-2017-11436?
CVE-2017-11436 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-11436?
Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dir-615.