Weak Security Configuration in D-Link DWR-932B Router
CVE-2016-10185

7.5HIGH

Key Information:

Vendor

D-Link

Vendor
CVE Published:
30 January 2017

What is CVE-2016-10185?

A vulnerability was identified in the D-Link DWR-932B router caused by a misconfiguration in the /var/miniupnpd.conf file, which includes the insecure directive 'secure_mode=no'. This setting can lead to adverse security implications, allowing unauthorized access through the device's universal plug and play (UPnP) functionality, potentially exposing the network to external threats.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.