Impact
The vulnerability exists in an unknown function of the vsftpd configuration file /etc/vsftpd.conf on D‑Link DIR‑823G firmware 1.0.2B05. Manipulating this configuration triggers a least‑privilege violation, allowing an attacker who can reach the device over the network to elevate privileges or bypass intended boundaries. The flaw can be exploited remotely, and a public exploit is available.
Affected Systems
Devices that run the D‑Link DIR‑823G router with firmware version 1.0.2B05 are impacted. No other firmware revisions are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 denotes a medium level of severity. No EPSS value is provided and the vulnerability is not included in CISA’s KEV catalog. Because an attacker can externally manipulate the vsftpd configuration and a public exploit exists, the risk of privilege escalation should be considered moderate to high in a network that exposes the device to the internet.
OpenCVE Enrichment