Description
There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the router's username and password (and other information) via a DEVICE.ACCOUNT value for SERVICES in conjunction with AUTHORIZED_GROUP=1%0a to getcfg.php. This could be used to control the router remotely.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T01:40:15.762Z
Reserved: 2019-10-11T00:00:00.000Z
Link: CVE-2019-17506
No data.
Status : Modified
Published: 2019-10-11T20:15:17.003
Modified: 2024-11-21T04:32:24.290
Link: CVE-2019-17506
No data.
OpenCVE Enrichment
No data.
Weaknesses