Impact
A weakness in the Web Interface of D‑link DIR‑823G firmware 1.0.2B05_20181207 allows remote manipulation of the file /etc/boa/boa.conf. Exploiting this flaw leads to a least‑privilege violation, effectively turning a low‑privileged user into a privileged one and enabling unauthorized configuration changes. The flaw is classified under CWE‑266 and CWE‑272, indicating inadequate permission checks and weak default permissions.
Affected Systems
The vulnerability affects the D‑link DIR‑823G firmware 1.0.2B05_20181207. No other versions are listed as affected.
Risk and Exploitability
The CVSS score of 7.7 classifies this as High severity. Exploitation requires remote access, a high level of complexity, and is considered difficult, though publicly available exploits exist. The EPSS score of <1% indicates a very low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation, but the potential impact warrants attention.
OpenCVE Enrichment