Impact
A flaw exists in the configuration file /etc/vsftpd.conf of D-Link DIR-842 firmware 2.01.B04 that can be manipulated to assign incorrect default permissions. This misconfiguration can potentially allow an attacker to read or modify files that should otherwise be protected, thereby leaking sensitive information or enabling further compromise. The description indicates that the vulnerability can be exploited remotely, though it requires a high level of complexity and is considered difficult to execute.
Affected Systems
The vulnerability affects D-Link DIR-842 routers running firmware version 2.01.B04. No other versions or variants are mentioned in the data.
Risk and Exploitability
The CVSS score of 2.3 reflects a low overall severity, and the EPSS score is not available, suggesting limited evidence of exploitation in the field. The vulnerability is not listed in the CISA KEV catalog. Exploitation would entail remote manipulation of the vsftpd configuration, requiring elevated knowledge and effort, which reduces the likelihood of widespread attacks. Nonetheless, the potential for unauthorized access due to improper file permissions warrants attention.
OpenCVE Enrichment