Vulnerability Description
Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_config/image_sign. This affects DIR-600 B1 V2.01 for WW, DIR-890L A1 v1.03, DIR-615 J1 v100 (for DCN), DIR-645 A1 v1.03, DIR-815 A1 v1.01, DIR-823 A1 v1.01, and DIR-842 C1 v3.00.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dir-600 B1 Firmware | 2.01 |
| Dlink | Dir-600 B1 | - |
| Dlink | Dir-615 J1 Firmware | 100 |
| Dlink | Dir-615 J1 | - |
| Dlink | Dir-645 A1 Firmware | 1.03 |
| Dlink | Dir-645 A1 | - |
| Dlink | Dir-815 A1 Firmware | 1.01 |
| Dlink | Dir-815 A1 | - |
| Dlink | Dir-823 A1 Firmware | 1.01 |
| Dlink | Dir-823 A1 | - |
| Dlink | Dir-842 C1 Firmware | 3.00 |
| Dlink | Dir-842 C1 | - |
| Dlink | Dir-890L A1 Firmware | 1.03 |
| Dlink | Dir-890L A1 | - |
Related Weaknesses (CWE)
References
- https://github.com/ChandlerChin/Dlink_vuls/blob/master/A%20hard%20coded%20telnetExploitThird Party Advisory
- https://github.com/ChandlerChin/Dlink_vuls/blob/master/A%20hard%20coded%20telnetExploitThird Party Advisory
FAQ
What is CVE-2019-18852?
CVE-2019-18852 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_config/image_sign. This affects DIR-600 B1 V2.01 for WW, DIR-890L ...
How severe is CVE-2019-18852?
CVE-2019-18852 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-18852?
Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dir-600 B1 Firmware, Dlink Dir-600 B1, Dlink Dir-615 J1 Firmware, Dlink Dir-615 J1, Dlink Dir-645 A1 Firmware.