TCP Relay Vulnerability in D-Link DIR-850L Routers
CVE-2017-14419

5.9MEDIUM

Key Information:

Vendor
D-Link
Vendor
CVE Published:
13 September 2017

Summary

The D-Link DIR-850L routers—specifically REV. A and REV. B with certain firmware versions—are vulnerable due to their NPAPI extension, which establishes a TCP relay for HTTP connections while also exposing a separate relay for HTTPS. This configuration can lead to potential security risks as it may allow unauthorized access to sensitive information sent through the mydlink Cloud Services, emphasizing the need for vigilance in network security practices.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.