D-Link Router Vulnerability Exposing Sensitive Files
CVE-2017-14424
7.8HIGH
What is CVE-2017-14424?
The D-Link DIR-850L routers (REV. A and REV. B) are susceptible to a security vulnerability stemming from improperly set file permissions on critical system files. Specifically, the /var/passwd file is accessible with 0666 permissions, allowing unauthorized users to read sensitive information, potentially leading to account compromise or further exploitation of the device. Users are advised to ensure they are running the latest firmware updates to mitigate these risks.