Authentication Bypass Vulnerability in D-Link DNR-326 NVR
CVE-2014-7858
9.8CRITICAL
Summary
The D-Link DNR-326 Network Video Recorder before version 2.10 Build 03 is vulnerable to an authentication bypass. Attackers can exploit this vulnerability by manipulating the username cookie parameter, enabling them to log in without proper authentication credentials. This flaw presents a serious risk by allowing unauthorized users to gain access to the device, potentially leading to further exploitation and data breaches.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved