Vulnerability Description
There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the router's username and password (and other information) via a DEVICE.ACCOUNT value for SERVICES in conjunction with AUTHORIZED_GROUP=1%0a to getcfg.php. This could be used to control the router remotely.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dir-868L B1 Firmware | 2.03 |
| Dlink | Dir-868L B1 | - |
| Dlink | Dir-817Lw A1 Firmware | 1.04 |
| Dlink | Dir-817Lw A1 | - |
Related Weaknesses (CWE)
References
- https://github.com/dahua966/Routers-vuls/blob/master/DIR-868/name%26passwd.pyExploitThird Party Advisory
- https://github.com/dahua966/Routers-vuls/blob/master/DIR-868/name%26passwd.pyExploitThird Party Advisory
FAQ
What is CVE-2019-17506?
CVE-2019-17506 is a vulnerability with a CVSS score of 9.8 (CRITICAL). There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the router's username and password (and other informatio...
How severe is CVE-2019-17506?
CVE-2019-17506 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-17506?
Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dir-868L B1 Firmware, Dlink Dir-868L B1, Dlink Dir-817Lw A1 Firmware, Dlink Dir-817Lw A1.