An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilege account) access, an attacker can intercept the response from a POST request to obtain "Admin" rights due to the admin password being displayed in XML.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-08-29T19:00:00
Updated: 2024-08-05T08:45:02.120Z
Reserved: 2018-06-24T00:00:00
Link: CVE-2018-12710
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-08-29T19:29:00.267
Modified: 2024-11-21T03:45:42.933
Link: CVE-2018-12710
Redhat
No data.