Description
A vulnerability was identified in D-Link DIR-842 2.01.B04. This impacts an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Such manipulation leads to incorrect default permissions. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult.
Published: 2026-08-15
Score: 2.3 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw exists in the configuration file /etc/vsftpd.conf of D-Link DIR-842 firmware 2.01.B04 that can be manipulated to assign incorrect default permissions. This misconfiguration can potentially allow an attacker to read or modify files that should otherwise be protected, thereby leaking sensitive information or enabling further compromise. The description indicates that the vulnerability can be exploited remotely, though it requires a high level of complexity and is considered difficult to execute.

Affected Systems

The vulnerability affects D-Link DIR-842 routers running firmware version 2.01.B04. No other versions or variants are mentioned in the data.

Risk and Exploitability

The CVSS score of 2.3 reflects a low overall severity, and the EPSS score is not available, suggesting limited evidence of exploitation in the field. The vulnerability is not listed in the CISA KEV catalog. Exploitation would entail remote manipulation of the vsftpd configuration, requiring elevated knowledge and effort, which reduces the likelihood of widespread attacks. Nonetheless, the potential for unauthorized access due to improper file permissions warrants attention.

Generated by OpenCVE AI on August 15, 2026 at 15:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to the latest version released by D‑Link that addresses the vsftpd configuration issue.
  • If an update is unavailable or delayed, manually edit /etc/vsftpd.conf to enforce secure defaults, ensuring that file permissions are set correctly and that no unintended write or read access is granted.
  • Restrict remote access to the FTP service by configuring firewall rules or disabling passive FTP if not required, limiting the attack surface for potential exploitation.

Generated by OpenCVE AI on August 15, 2026 at 15:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 15 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in D-Link DIR-842 2.01.B04. This impacts an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Such manipulation leads to incorrect default permissions. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult.
Title D-Link DIR-842 vsftpd vsftpd.conf default permission
First Time appeared D-link
D-link dir-842
Weaknesses CWE-266
CWE-276
CPEs cpe:2.3:h:d-link:dir-842:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link dir-842
References
Metrics cvssV2_0

{'score': 2.1, 'vector': 'AV:N/AC:H/Au:S/C:N/I:P/A:N/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.1, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-15T12:00:08.899Z

Reserved: 2026-08-14T18:45:04.797Z

Link: CVE-2026-19893

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T12:16:32.543

Modified: 2026-08-15T12:16:32.543

Link: CVE-2026-19893

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-15T16:00:07Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-276

    Incorrect Default Permissions